CVE-2026-34197
Apache ActiveMQ Code Injection via Improper Input Validation
05:03 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Apache ActiveMQ — CVE-2026-34197
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the pro…
CVE-2025-21043
Samsung Mobile Out-of-Bounds Write in libimagecodec.quram.so
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2025-21333
Windows Hyper-V NT Kernel Integration VSP Heap Buffer Overflow Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21334
Windows Hyper-V NT Kernel Integration VSP Use-After-Free Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21335
Windows Hyper-V NT Kernel Integration VSP Use-After-Free Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21391
Microsoft Windows Storage Link Following Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Storage Link Following Vulnerability — Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavail…
CVE-2025-21418
Windows WinSock Ancillary Function Driver Heap Buffer Overflow Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability — Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain S…
CVE-2025-22457
Ivanti Connect Secure Stack-Based Buffer Overflow RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability — Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code exec…
CVE-2025-23006
SonicWall SMA1000 Deserialization RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SonicWall SMA1000 Appliances Deserialization Vulnerability — SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitra…
CVE-2025-23209
Craft CMS Database Backup Path Code Injection RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Craft CMS Code Injection Vulnerability — Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
CVE-2025-3928
Commvault Web Server Remote Webshell Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Commvault Web Server Unspecified Vulnerability — Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.
CVE-2025-40536
SolarWinds Web Help Desk Authentication Bypass Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SolarWinds Web Help Desk Security Control Bypass Vulnerability — SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2025-4632
Samsung MagicINFO 9 Server Path Traversal - Arbitrary File Write
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Samsung MagicINFO 9 Server Path Traversal Vulnerability — Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.
CVE-2025-47812
Wing FTP Server Null Byte Injection - Arbitrary Lua Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability — Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execut…
CVE-2025-47827
IGEL OS Secure Boot Bypass via Expired Cryptographic Key Verification
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesyst…
CVE-2025-48384
Git Link Following Vulnerability in Configuration File Handling
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Git Link Following Vulnerability — Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2025-48927
TeleMessage TM SGNL Exposed Heap Dump Endpoint - Insecure Default
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability — TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed h…
CVE-2025-49113
RoundCube Webmail Authenticated RCE via Deserialization in Settings Upload
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
RoundCube Webmail Deserialization of Untrusted Data Vulnerability — RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/setti…
CVE-2025-49704
Microsoft SharePoint Code Injection Vulnerability (CVE-2025-49704)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft SharePoint Code Injection Vulnerability — Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for C…
CVE-2025-5086
DELMIA Apriso Deserialization RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability — Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.
CVE-2025-5419
Chromium V8 Out-of-Bounds Read/Write Heap Corruption Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability — Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple we…
CVE-2025-54236
Adobe Commerce REST API Account Takeover via Input Validation Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-54253
Adobe Experience Manager Forms JEE Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-54313
Prettier eslint-config-prettier Malicious Code Execution via Install Script
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability — Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2025-59230
Windows Remote Access Connection Manager Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
CVE-2025-61882
Oracle E-Business Suite BI Publisher Integration Critical Remote Compromise
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle E-Business Suite Unspecified Vulnerability — Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. …
CVE-2025-61884
Oracle E-Business Suite SSRF Vulnerability in Configurator Runtime
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
CVE-2025-61932
Motex LANSCOPE Endpoint Manager Arbitrary Code Execution via Unverified Communication
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sendin…
CVE-2025-64446
Fortinet FortiWeb Unauthenticated Path Traversal RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet FortiWeb Path Traversal Vulnerability — Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-68461
RoundCube Webmail SVG Animate Tag Cross-Site Scripting Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
RoundCube Webmail Cross-site Scripting Vulnerability — RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2025-68645
Zimbra Collaboration Suite PHP Remote File Inclusion RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal req…
CVE-2025-8110
Gogs PutContents API Path Traversal and Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-8876
N-able N-Central Command Injection via Unsanitized User Input
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
N-able N-Central Command Injection Vulnerability — N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-9242
WatchGuard Firebox iked Out-of-Bounds Write Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
WatchGuard Firebox Out-of-Bounds Write Vulnerability — WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-9377
TP-Link Router OS Command Injection in Parental Control (CVE-2025-9377)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-servic…
CVE-2026-25654
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u
09:48 KSA
HIGH
CVSS 8.8
CWE-639
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the abil…
CVE-2026-27668
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U
09:48 KSA
HIGH
CVSS 8.8
CWE-266
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and gr…
CVE-2026-3464
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat
18:48 KSA
HIGH
CVSS 8.8
CWE-22
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that…
CVE-2026-40040
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file
03:25 KSA
HIGH
CVSS 8.8
CWE-434
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directori…
CVE-2026-40459
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt
12:32 KSA
HIGH
CVSS 8.8
CWE-90
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations.
This issue was fixed in PAC4J versio…
CVE-2026-6157
A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit…
CVE-2026-6168
A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid5g causes stack-based buffer overflow. Remote exploitation of the attack is possible. The e…
CVE-2026-6186
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argument NatBind leads to buffer overflow. The attack is possible to be carried out remo…
CVE-2026-6194
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_410188 of the file /boafrm/formWlanSetup of the component HTTP Request Handler. This manipulation of the argument wan-url causes stack-based buffer overflow. Remo…
CVE-2026-6196
A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit i…
CVE-2026-6198
A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit…
CVE-2026-6199
A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting.
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public an…
CVE-2026-6200
A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil
03:25 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploi…
CVE-2026-27928
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
21:54 KSA
HIGH
CVSS 8.7
CWE-20
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-40516
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t
18:48 KSA
HIGH
CVSS 8.3
CWE-918
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by manipulating tool parameters without proper validation of target addresses. Attacker…
CVE-2026-5718
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in
20:43 KSA
HIGH
CVSS 8.1
CWE-434
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.6. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces…
CVE-2026-27912
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
21:54 KSA
HIGH
CVSS 8.0
CWE-285
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2025-36568
Dell PowerProtect Data Domain BoostFS Credential Protection Vulnerability
12:32 KSA
HIGH
CVSS 7.8
CWE-522
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged…
CVE-2026-23657
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
21:54 KSA
HIGH
CVSS 7.8
CWE-416
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-26143
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
21:54 KSA
HIGH
CVSS 7.8
CWE-20
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-26183
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
21:54 KSA
HIGH
CVSS 7.8
CWE-284
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
CVE-2026-27238
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
15:49 KSA
HIGH
CVSS 7.8
CWE-122
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…
CVE-2026-27283
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a
15:49 KSA
HIGH
CVSS 7.8
CWE-416
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-27284
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr
21:54 KSA
HIGH
CVSS 7.8
CWE-125
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the con…
CVE-2026-27291
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul
21:54 KSA
HIGH
CVSS 7.8
CWE-787
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fi…
CVE-2026-27924
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
21:54 KSA
HIGH
CVSS 7.8
CWE-416
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-40527
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted
00:49 KSA
HIGH
CVSS 7.8
CWE-78
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF paramete…
CVE-2026-27913
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
21:54 KSA
HIGH
CVSS 7.7
CWE-20
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-34853
Permission bypass vulnerability in the LBS module.
Impact: Successful exploitation of this vulnerability may affect avai
03:25 KSA
HIGH
CVSS 7.7
CWE-270
Permission bypass vulnerability in the LBS module.
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-26154
Windows Server Update Service Input Validation Vulnerability
21:54 KSA
HIGH
CVSS 7.5
CWE-20
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
CVE-2026-26171
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
21:54 KSA
HIGH
CVSS 7.5
CWE-400
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-40481
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi
02:00 KSA
HIGH
CVSS 7.5
CWE-400
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cau…
CVE-2026-40515
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil
18:48 KSA
HIGH
CVSS 7.5
CWE-863
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attackers can invoke the built-in grep and glob tools with sensitive root directories …
CVE-2026-4352
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp
09:48 KSA
HIGH
CVSS 7.5
CWE-89
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf(…
CVE-2026-4659
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV
06:18 KSA
HIGH
CVSS 7.5
CWE-22
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions…
CVE-2026-5710
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t
20:43 KSA
HIGH
CVSS 7.5
CWE-22
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for em…
CVE-2026-24032
SINEC NMS Authentication Bypass in UMC Component (CVE-2026-24032)
09:48 KSA
HIGH
CVSS 7.3
CWE-347
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component.
This could allow an unauthenticated remote attacker to bypass a…
CVE-2026-34856
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availabi
03:25 KSA
HIGH
CVSS 7.3
CWE-362
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-35603
Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide defaul
00:51 KSA
HIGH
CVSS 7.3
CWE-426
Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData direc…
CVE-2026-6153
SQL Injection in Vehicle Showroom Management System StaffDetailsFunction.php
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument STAFF_ID leads to sql injection. The attack can be launched remotely. The exploit …
CVE-2026-6158
Totolink N300RH Remote Command Injection via Upgrade Function
03:25 KSA
HIGH
CVSS 7.3
CWE-77
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published…
CVE-2026-6161
A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chat
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argument msg can lead to sql injection. It is possible to launch the attack remotely. …
CVE-2026-6163
SQL Injection in Lost and Found Thing Management 1.0 /catageory.php
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection. It is possible to launch the attack remotely. The ex…
CVE-2026-6164
SQL Injection in Lost and Found Thing Management 1.0 /addcat.php
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection. The attack can be initiated remotely. The exploit has been rele…
CVE-2026-6165
SQL Injection in Vehicle Showroom Management System Login Module
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The explo…
CVE-2026-6166
SQL Injection in Vehicle Showroom Management System UpdateVehicleFunction
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initia…
CVE-2026-6167
A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be use…
CVE-2026-6182
A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. T…
CVE-2026-6183
A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is …
CVE-2026-6187
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from re…
CVE-2026-6188
SQL Injection in SourceCodester Pharmacy Sales and Inventory System 1.0
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has b…
CVE-2026-6189
SQL Injection in SourceCodester Pharmacy System Login Function
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotel…
CVE-2026-6193
SQL Injection in PHPGurukul Daily Expense Tracking System 1.1 /register.php
03:25 KSA
HIGH
CVSS 7.3
CWE-74
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to t…
CVE-2026-6224
NocoDB Plugin Sandbox Escape Vulnerability in Workflow JavaScript
05:35 KSA
HIGH
CVSS 7.3
CWE-264
A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The a…
CVE-2026-6490
A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f
12:32 KSA
HIGH
CVSS 7.3
CWE-74
A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/deletecourse.php of the component GET Request Parameter Handler. This manipulation of the argument ID causes sql injection. The attack…
CVE-2026-23776
Dell PowerProtect Data Domain Certificate Validation Privilege Escalation
12:32 KSA
HIGH
CVSS 7.2
CWE-295
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerabil…
CVE-2026-3017
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P
09:48 KSA
HIGH
CVSS 7.2
CWE-502
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possi…
CVE-2026-40038
Pachno 1.0.6 Stored XSS via Unsanitized POST Parameters
03:25 KSA
HIGH
CVSS 7.2
CWE-79
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can inject scripts through the value, comment_body, article_content, description, and …
CVE-2026-4388
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box
09:48 KSA
HIGH
CVSS 7.2
CWE-79
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tag…
CVE-2026-5231
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al
06:18 KSA
HIGH
CVSS 7.2
CWE-79
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_so…
CVE-2026-6227
BackWPup WordPress Plugin Local File Inclusion via REST API
09:48 KSA
HIGH
CVSS 7.2
CWE-22
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive `str_replace()` sanitization of path traversal sequences.…
CVE-2026-6483
Wavlink WL-WN530H4 Remote OS Command Injection in internet.cgi
12:32 KSA
HIGH
CVSS 7.2
CWE-77
A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has been made public an…
CVE-2026-33704
Chamilo LMS Arbitrary File Upload via BigUpload .pht Extension Bypass
03:25 KSA
HIGH
CVSS 7.1
CWE-434
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body becomes the file content. While …
CVE-2026-33892
Industrial Edge Management Authentication Bypass on Remote Connections
11:48 KSA
HIGH
CVSS 7.1
CWE-305
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do …
CVE-2026-34256
Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke
05:35 KSA
HIGH
CVSS 7.1
CWE-862
Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is su…
CVE-2026-40518
ByteDance DeerFlow Path Traversal in Custom-Agent Creation
20:43 KSA
HIGH
CVSS 7.1
CWE-22
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influe…
CVE-2026-4344
Autodesk Fusion Stored XSS in Delete Confirmation Dialog via Component Names
15:49 KSA
HIGH
CVSS 7.1
CWE-79
A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulner…
CVE-2026-4345
Autodesk Fusion Stored XSS in Design Names CSV Export
15:49 KSA
HIGH
CVSS 7.1
CWE-79
A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary co…
CVE-2026-4369
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and
15:49 KSA
HIGH
CVSS 7.1
CWE-79
A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage thi…
CVE-2026-6421
MobaXterm msimg32.dll Uncontrolled Search Path Vulnerability
06:18 KSA
HIGH
CVSS 7.0
CWE-426
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It i…
CVE-2026-3488
WP Statistics Plugin Missing Authorization on AJAX Handlers (CVE-2026-3488)
08:36 KSA
MEDIUM
CVSS 6.5
CWE-862
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_…
CVE-2026-4666
wpForo Forum Plugin Authorization Bypass via Variable Extraction
11:00 KSA
MEDIUM
CVSS 6.5
CWE-862
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action …
CVE-2026-4817
MasterStudy LMS WordPress Plugin SQL Injection via REST API
08:36 KSA
MEDIUM
CVSS 6.5
CWE-89
The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' parameters in the /lms/stm-lms/order/items REST API endpoint in versions up to and including 3.7.25. This is du…
CVE-2026-6080
Tutor LMS WordPress Plugin SQL Injection Vulnerability (CVE-2026-6080)
13:16 KSA
MEDIUM
CVSS 6.5
CWE-89
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it poss…
CVE-2026-1572
Livemesh Elementor Plugin Stored XSS and Authorization Bypass
04:09 KSA
MEDIUM
CVSS 6.4
CWE-79
The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0. This is due to missing authorization checks on the AJAX handler `lae_admin_ajax…
CVE-2026-2434
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute
07:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, …
CVE-2026-2840
WordPress Email Encoder Plugin Stored XSS via eeb_mailto Shortcode
04:09 KSA
MEDIUM
CVSS 6.4
CWE-79
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it pos…
CVE-2026-3875
BetterDocs WordPress Plugin Stored XSS via Feedback Form Shortcode
04:09 KSA
MEDIUM
CVSS 6.4
CWE-79
The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. Thi…
CVE-2026-5162
Royal Addons Elementor Instagram Feed Widget Stored XSS Vulnerability
08:36 KSA
MEDIUM
CVSS 6.4
CWE-79
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes i…
CVE-2026-6488
QueryMine SMS SQL Injection in admin/editcourse.php GET Parameter
22:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file admin/editcourse.php of the component GET Request Parameter Handler. The manipulation of the argument ID leads to sql injection. The…
CVE-2026-6489
QueryMine SMS Unrestricted File Upload in Admin Panel
22:16 KSA
MEDIUM
CVSS 6.3
CWE-284
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation of the argument image results in unrestri…
CVE-2026-6497
TinyFileManager SSRF Vulnerability in File Upload Handler
00:48 KSA
MEDIUM
CVSS 6.3
CWE-918
A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes serve…
CVE-2026-3355
Customer Reviews for WooCommerce Plugin Reflected XSS via crsearch Parameter
04:09 KSA
MEDIUM
CVSS 6.1
CWE-79
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica…
CVE-2026-3369
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
04:09 KSA
MEDIUM
CVSS 5.4
CWE-79
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authentic…
CVE-2026-6496
TinyFileManager Path Traversal via POST Parameter Handler
22:16 KSA
MEDIUM
CVSS 5.4
CWE-22
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. Th…
CVE-2026-0718
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor
04:09 KSA
MEDIUM
CVSS 5.3
CWE-862
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and including, 5.0.5. This makes i…
CVE-2026-4160
Fluent Forms IDOR Vulnerability in Stripe SCA Payment Status Modification
04:09 KSA
MEDIUM
CVSS 5.3
CWE-639
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and o…
CVE-2026-5234
LatePoint WordPress Plugin Insecure Direct Object Reference in Payment Handler
13:16 KSA
MEDIUM
CVSS 5.3
CWE-639
The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no auth…
CVE-2026-5427
Kubio WordPress Plugin Arbitrary File Upload via REST API
13:16 KSA
MEDIUM
CVSS 5.3
CWE-862
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_pre_insert_{post_type} filter for posts, p…
CVE-2026-5502
Tutor LMS Authorization Bypass in Course Content Manipulation
13:16 KSA
MEDIUM
CVSS 5.3
CWE-862
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The functio…
CVE-2026-5797
Quiz And Survey Master Plugin Arbitrary Shortcode Execution Vulnerability
13:16 KSA
MEDIUM
CVSS 5.3
CWE-74
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pas…
CVE-2026-6491
libvips Heap Buffer Overflow in Deprecated im_minpos_vec Function
22:16 KSA
MEDIUM
CVSS 5.3
CWE-119
A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack ha…
CVE-2026-6492
Information Disclosure in Hotel Booking System Health Check Endpoint
22:16 KSA
MEDIUM
CVSS 5.3
CWE-200
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in infor…
CVE-2026-6494
AAP MCP Server Log Injection via Unsanitized toolsetroute Parameter
22:16 KSA
MEDIUM
CVSS 5.3
CWE-117
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to…