CVE-2026-40411
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
23:15 KSA
CRITICAL
CVSS 9.9
CWE-20
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
CVE-2026-45321
TanStack TanStack — CVE-2026-45321
TanStack contains an unspecified vulnerability that allowed malicious versions of the
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
TanStack TanStack — CVE-2026-45321
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
Required Action: Apply mitigations per vendor ins…
CVE-2026-48027
Nx Console Malicious Code Vulnerability Harvests Credentials
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Nx Nx Console — CVE-2026-48027
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and i…
CVE-2026-48172
LiteSpeed cPanel Plugin — CVE-2026-48172
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exp
05:18 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
LiteSpeed cPanel Plugin — CVE-2026-48172
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Required Action: Apply m…
CVE-2026-8398
Daemon Daemon Tools Lite — CVE-2026-8398
Daemon Tools contains an unspecified vulnerability that has a high impact on co
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Daemon Daemon Tools Lite — CVE-2026-8398
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services…
CVE-2025-41669
PLCnext Control Arbitrary Code Execution via Unverified APP Installation
15:05 KSA
HIGH
CVSS 8.8
CWE-347
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution …
CVE-2026-42184
Tauri is_local_url() Remote URL Misclassification on Windows/Android
09:36 KSA
HIGH
CVSS 8.8
CWE-918
Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme …
CVE-2026-5065
IBM Controller Hard-Coded Credentials Vulnerability (CVE-2026-5065)
21:13 KSA
HIGH
CVSS 8.8
CWE-798
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVE-2026-8179
IBM Aspera Buffer Overflow in asperahttpd Component (CVE-2026-8179)
21:13 KSA
HIGH
CVSS 8.8
CWE-121
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could all…
CVE-2026-8409
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/…
CVE-2026-8410
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/…
CVE-2026-8411
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/…
CVE-2026-8412
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/…
CVE-2026-8413
Concrete CMS 9 CSRF Vulnerability in Bulk Page Design Dialog
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/…
CVE-2026-8414
Concrete CMS 9 CSRF Vulnerability in Event Duplication Dialog
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/S…
CVE-2026-8415
Concrete CMS 9 CSRF Vulnerability in Express Association Reorder
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N…
CVE-2026-8416
Concrete CMS 9 CSRF Vulnerability in File Favorite Folder Function
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:…
CVE-2026-8427
Concrete CMS 9 CSRF Vulnerability in removeFavoriteFolder Function
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/…
CVE-2026-8432
Concrete CMS 9 CSRF Vulnerability in Backend File Star Controller
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N…
CVE-2026-8433
Concrete CMS 9 CSRF Vulnerability in File Rescan Backend Controller
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA…
CVE-2026-8434
Concrete CMS 9 CSRF Vulnerability in File Rescan Function
04:00 KSA
HIGH
CVSS 8.8
CWE-352
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N…
CVE-2026-8787
Firebase Support & Chat Management WordPress Plugin Privilege Escalation
09:18 KSA
HIGH
CVSS 8.8
CWE-269
The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email…
CVE-2026-8832
WPCode Plugin RCE via XML-RPC Authenticated Code Execution
21:13 KSA
HIGH
CVSS 8.8
CWE-94
The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_ty…
CVE-2026-9632
UTT HiPER 1250GW Stack Buffer Overflow in Web Management Interface
09:18 KSA
HIGH
CVSS 8.8
CWE-119
A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overfl…
CVE-2026-9631
UTT HiPER 1250GW Stack Buffer Overflow in Web Management Interface
03:18 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in s…
CVE-2026-9627
UTT HiPER 1200GW Buffer Overflow in Web Management Interface
03:18 KSA
HIGH
CVSS 8.8
CWE-119
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can …
CVE-2026-9380
A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is the function formL2TPSetup of the file
16:36 KSA
HIGH
CVSS 8.8
CWE-119
A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to buffer overflow. The attack can be launched…
CVE-2026-9381
A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerability is the function formPPPoESetup of
16:36 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. The att…
CVE-2026-9382
A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform
16:36 KSA
HIGH
CVSS 8.8
CWE-119
A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Executing a manipulation of the argument pptpUserName can lead to buffer overflow. The attack may be launc…
CVE-2026-9389
A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function frmL7ImForm of the file /gof
20:23 KSA
HIGH
CVSS 8.8
CWE-119
A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may …
CVE-2026-9393
A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform
20:23 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and…
CVE-2026-9399
A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file
20:23 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. It is possible to …
CVE-2026-9403
A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the fi
20:23 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. The attack may be initiated…
CVE-2026-9401
A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/
20:23 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to buffer overflow. The attack can be initiated remo…
CVE-2025-30028
Active Backup for Business Arbitrary File Read via SQL Injection
21:13 KSA
HIGH
CVSS 8.6
CWE-89
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2026-40851
cfgparser Local Code Execution via Crafted Configuration Files
21:13 KSA
HIGH
CVSS 8.4
CWE-1287
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
CVE-2026-7365
IBM Operations Analytics Default Credentials Authentication Bypass
21:13 KSA
HIGH
CVSS 8.4
CWE-1392
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
CVE-2026-9312
GitHub Enterprise Server SSRF Vulnerability via Upload Endpoint
03:16 KSA
HIGH
CVSS 8.2
CWE-918
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal cont…
CVE-2025-13392
Synology DSM SSO Authentication Bypass via Distinguished Name
21:13 KSA
HIGH
CVSS 8.1
CWE-754
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN…
CVE-2026-41071
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w
23:15 KSA
HIGH
CVSS 8.1
CWE-125
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoRe…
CVE-2026-42790
Erlang OTP DNS nameConstraints Bypass via CommonName Fallback
21:01 KSA
HIGH
CVSS 8.1
CWE-295
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification.
Two flaws combine to allow a subordinate CA whose DNS nameConstraints are…
CVE-2026-48906
Tassos Framework Plugin Arbitrary File Deletion Vulnerability
21:13 KSA
HIGH
CVSS 8.1
CWE-284
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
CVE-2026-8994
Login with NEAR WordPress Plugin Authentication Bypass (CVE-2026-8994)
09:18 KSA
HIGH
CVSS 8.1
CWE-287
The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplie…
CVE-2026-9397
Besen BS20 EV Charging Station OTA Update Authorization Bypass
20:23 KSA
HIGH
CVSS 8.1
CWE-266
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out remote…
CVE-2023-52945
Synology BeeDrive OpenSSL DLL Uncontrolled Search Path Code Execution
21:13 KSA
HIGH
CVSS 7.8
CWE-427
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.
CVE-2025-41670
Local Privilege Escalation via Insecure File Handling in System Services
15:05 KSA
HIGH
CVSS 7.8
CWE-427
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not suffi…
CVE-2026-3623
IBM Netezza Privilege Escalation to Root (CVE-2026-3623)
21:13 KSA
HIGH
CVSS 7.8
CWE-250
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s p…
CVE-2026-45136
Code Injection in claude-code-cache-fix quota-statusline.sh String Interpolation
03:16 KSA
HIGH
CVSS 7.8
CWE-78
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-con…
CVE-2025-14713
Synology C2 Identity Edge Server Exposed Dangerous Method Credential Disclosure
21:13 KSA
HIGH
CVSS 7.5
CWE-749
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
CVE-2026-3366
IBM InfoSphere Optim Path Traversal Vulnerability (CVE-2026-3366)
21:13 KSA
HIGH
CVSS 7.5
CWE-22
IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequenc…
CVE-2026-40622
NLnet Labs Unbound Ghost Domain Names TTL Extension Vulnerability
04:00 KSA
HIGH
CVSS 7.5
CWE-346
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to …
CVE-2026-40810
Unauthenticated SQL Injection in userinfo Endpoint (CVE-2026-40810)
15:05 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40811
Unauthenticated SQL Injection in ssoabstractservice - CWE-89
15:05 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40812
Unauthenticated SQL Injection in getLiveValues sn Parameter
15:05 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40813
Unauthenticated SQL Injection in getLiveValues tagid Parameter
15:05 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40814
Unauthenticated SQL Injection in dataapi.php _mb24confi_getTagAlarm Function
15:05 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40815
Unauthenticated SQL Injection in _mb24api_getUserAccount Function
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40816
Unauthenticated SQL Injection in mb24alarm.php _mb24confi_getTagAlarm Function
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40817
Unauthenticated SQL Injection in getAlarmProfiles Function
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40818
Unauthenticated SQL Injection in _mb24confi_getDevice Function
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40819
Unauthenticated SQL Injection in sync_data24 Task
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40850
Unauthenticated SQL Injection in getAccountData Function
21:13 KSA
HIGH
CVSS 7.5
CWE-89
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-42459
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to vali
21:18 KSA
HIGH
CVSS 7.5
CWE-20
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Data Management) service. An unauthenticated attacker can inject control characters…
CVE-2026-44378
Botan Cryptography Library BER Parser Denial of Service
21:01 KSA
HIGH
CVSS 7.5
CWE-407
Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded a…
CVE-2026-44660
UltraJSON Memory Leak in ujson.dump() File Write Exception Handling
03:16 KSA
HIGH
CVSS 7.5
CWE-401
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each fa…
CVE-2026-8180
IBM Aspera High-Speed Transfer DoS via Null Pointer Dereference
21:13 KSA
HIGH
CVSS 7.5
CWE-476
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticat…
CVE-2026-9200
Query Shortcode Plugin LFI Vulnerability Allows PHP Code Execution
09:18 KSA
HIGH
CVSS 7.5
CWE-98
The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .ph…
CVE-2026-9372
ItzCrazyKns Vane Model Provider API SSRF via baseURL Parameter
16:36 KSA
HIGH
CVSS 7.3
CWE-918
A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the…
CVE-2026-9606
SQL Injection in itsourcecode Courier Management System 1.0 manage_user.php
03:18 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the …
CVE-2026-9383
SQL Injection in itsourcecode Electronic Judging System Login
20:23 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been d…
CVE-2024-56462
IBM QRadar Backup Archive Privilege Escalation (CVE-2024-56462)
21:13 KSA
HIGH
CVSS 7.2
CWE-530
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.
CVE-2026-3375
LiteSpeed Cache WordPress Plugin Stored XSS via REST API CSS Endpoints
15:05 KSA
HIGH
CVSS 7.2
CWE-79
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud c…
CVE-2026-40852
Configuration Generator Command Injection Leading to Code Execution
21:13 KSA
HIGH
CVSS 7.2
CWE-78
A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss o…
CVE-2026-5509
Archer BE450/BE7200 v1 Authenticated Command Injection Vulnerability
21:01 KSA
HIGH
CVSS 7.2
CWE-20
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can le…
CVE-2026-6169
WordPress affiliate-toolkit Plugin RCE via BladeOne Template Injection
21:13 KSA
HIGH
CVSS 7.2
CWE-94
The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and execu…
CVE-2026-8134
Concrete CMS Path Traversal and RCE via Composer Form Layout
04:00 KSA
HIGH
CVSS 7.2
CWE-23
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitr…
CVE-2026-8135
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex
04:00 KSA
HIGH
CVSS 7.2
CWE-502
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF === true…
CVE-2026-8143
HBook WordPress Plugin Stored XSS via Country/State Parameters
21:13 KSA
HIGH
CVSS 7.2
CWE-79
The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it …
CVE-2026-1718
IBM Db2 Denial of Service via Malformed Query with Autonomous Transactions
21:13 KSA
HIGH
CVSS 7.1
CWE-770
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
CVE-2026-1933
Samba NTFS Reparse Point Access Control Bypass on Read-Only Shares
21:13 KSA
HIGH
CVSS 7.1
CWE-284
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations…
CVE-2026-40833
Unauthenticated SQL Injection in dash.php saveDashboardLayout Function
21:13 KSA
HIGH
CVSS 7.1
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting entries…
CVE-2026-40834
Unauthenticated SQL Injection in dash_layout.php saveDashboardLayout Function
21:13 KSA
HIGH
CVSS 7.1
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special elements in a SQL INSERT command allowing for reading the whole database and inserting …
CVE-2026-40836
SQL Injection in inmessage Model Allows Unauthenticated Database Access
21:13 KSA
HIGH
CVSS 7.1
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. Thi…
CVE-2026-7528
IBM Langflow OSS Uncontrolled Resource Consumption DoS Vulnerability
21:13 KSA
HIGH
CVSS 7.1
CWE-400
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
CVE-2024-11399
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des
19:42 KSA
MEDIUM
CVSS 6.8
CWE-552
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.
CVE-2026-9704
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an ove
11:23 KSA
MEDIUM
CVSS 6.8
CWE-1284
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fal…
CVE-2026-9603
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown
07:48 KSA
MEDIUM
CVSS 6.5
CWE-862
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. …
CVE-2025-0898
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and
01:03 KSA
MEDIUM
CVSS 6.5
CWE-73
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of a…
CVE-2026-2340
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections
09:54 KSA
MEDIUM
CVSS 6.5
CWE-280
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write…
CVE-2026-3279
The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
00:32 KSA
MEDIUM
CVSS 6.5
CWE-862
The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function in all versions up to, and including, 1.4.1. This is due to the function only verifying a nonce …
CVE-2026-3676
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (include
09:54 KSA
MEDIUM
CVSS 6.5
CWE-1284
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic …
CVE-2026-40831
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40832
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40835
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40837
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40838
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40839
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40840
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40841
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40842
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi
21:16 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40843
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40844
Unauthenticated SQL Injection in Dashboard View - CVE-2026-40844
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40845
Unauthenticated SQL Injection in devices_configuration View
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuration view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40846
Unauthenticated SQL Injection in System Views (CVE-2026-40846)
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40847
Unauthenticated SQL Injection in system_tag View
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40848
Unauthenticated SQL Injection in Tag View Functionality
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-40849
Unauthenticated SQL Injection in user_alarmprofile View
23:14 KSA
MEDIUM
CVSS 6.5
CWE-89
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
CVE-2026-44318
free5GC BSF Race Condition in Subscription Handler Causes DoS
11:23 KSA
MEDIUM
CVSS 6.5
CWE-362
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscriptions map. The handler first reads the map under RLock() via BSFContext.GetSubscr…
CVE-2026-47076
hackney URL Normalization SSRF - Percent-Encoding Bypass
20:39 KSA
MEDIUM
CVSS 6.5
CWE-436
Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{} record. OTP's uri_string:parse/1 and inet:parse_address/1 do not decode percent-…
CVE-2026-47118
Agent Zero Path Traversal Vulnerability Allows Unauthorized File Access
11:23 KSA
MEDIUM
CVSS 6.5
CWE-22
Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, which relies solely on an extension allowlist while the path containment check is ex…
CVE-2026-48684
FastNetMon NetFlow v9 Options Template Out-of-Bounds Read
20:39 KSA
MEDIUM
CVSS 6.5
CWE-125
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) iterates until scopes_offset reaches…
CVE-2026-48685
FastNetMon BGP Attribute Length Parsing Out-of-Bounds Memory Access
20:39 KSA
MEDIUM
CVSS 6.5
CWE-130
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and…
CVE-2026-6936
IBM i ILE Compiler Uncontrolled Recursion DoS Vulnerability
11:23 KSA
MEDIUM
CVSS 6.5
CWE-674
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific…
CVE-2026-8405
IBM Guardium Data Protection LTR Credential Exposure in Debug Mode
11:23 KSA
MEDIUM
CVSS 6.5
CWE-200
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
CVE-2026-9035
IBM Aspera Path Traversal Arbitrary File Read Vulnerability
11:23 KSA
MEDIUM
CVSS 6.5
CWE-22
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticat…
CVE-2026-2030
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output …
CVE-2026-3895
WPBakery Page Builder Addons Stored XSS via AJAX Handler
02:50 KSA
MEDIUM
CVSS 6.4
CWE-862
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handl…
CVE-2026-3896
Livemesh SiteOrigin Widgets WordPress Plugin Stored XSS via AJAX
02:50 KSA
MEDIUM
CVSS 6.4
CWE-862
The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a…
CVE-2026-3897
Livemesh Addons Beaver Builder WordPress Plugin Stored XSS via AJAX
02:50 KSA
MEDIUM
CVSS 6.4
CWE-862
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler ver…
CVE-2026-6565
The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulner
10:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insuffici…
CVE-2026-8040
The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute
13:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenti…
CVE-2026-8042
The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut
10:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribute in the 'github' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for aut…
CVE-2026-8048
The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode att
13:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 due to insufficient input sanitization and output escaping. This makes it possible…
CVE-2026-8698
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version
16:16 KSA
MEDIUM
CVSS 6.4
CWE-79
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode() function, which renders the 'width' (and 'height') shortcode attribute directly…
CVE-2026-8701
The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `tit
16:16 KSA
MEDIUM
CVSS 6.4
CWE-79
The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. This is due to insufficient input sanitization and output escaping on shortcode att…
CVE-2026-8702
The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribut
16:16 KSA
MEDIUM
CVSS 6.4
CWE-79
The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insufficient output escaping in the gbi_toprint_shortcode() function, which concatenates the raw shortcode attri…
CVE-2026-8703
The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ver
16:16 KSA
MEDIUM
CVSS 6.4
CWE-79
The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut…
CVE-2026-8837
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi
12:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenti…
CVE-2026-8842
The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcod
12:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes ('id' and 'name') in the…
CVE-2026-8844
The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in v
12:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to insufficient input sanitization and output escaping on the 'url' (and 'button') shortcode attributes in the …
CVE-2026-8845
The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortco
12:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user-supplied 'width' and 'height' shortcode att…
CVE-2026-8846
The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes ('title', 'align', and 'width') in the…
CVE-2026-8847
The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in versio
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute, which is interpolated directly into an HTML iframe 's…
CVE-2026-8866
The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortco
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes (userid, albumid, a…
CVE-2026-8867
The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcatego
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attr…
CVE-2026-8868
The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortc
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (autocom…
CVE-2026-8869
Stored XSS in Mutual Funds Data WordPress Plugin Title Attribute
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping on the user supplied 'title' attribute in the mf…
CVE-2026-8870
Team Master WordPress Plugin Stored XSS via Shortcode Attributes
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authent…
CVE-2026-8871
Formidable Kinetic WordPress Plugin Stored XSS via kinetic_link Shortcode
14:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'w…
CVE-2026-8872
The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-s
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in the sho…
CVE-2026-8873
The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri…
CVE-2026-8875
The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'co
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied shortcode a…
CVE-2026-8877
Responsive Video Embedder WordPress Plugin Stored XSS via Shortcode
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'l…
CVE-2026-8884
Instant-Quote.co Plugin Stored XSS via Shortcode Attributes
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker…
CVE-2026-8886
hk_shortcode WordPress Plugin Stored XSS via title-plane Shortcode
19:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes in the huankong_post_…
CVE-2026-8887
Listen Shortcode WordPress Plugin Stored XSS Vulnerability
22:02 KSA
MEDIUM
CVSS 6.4
CWE-79
The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes (src, start, end) in the listenE…
CVE-2026-8891
The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, 1.1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes ('width' and 'heigh…
CVE-2026-8894
The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in the iwr_tooltip() sho…
CVE-2026-8897
The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 0.1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri…
CVE-2026-8898
Events In City WordPress Plugin Stored XSS via org-events Shortcode
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to insufficient input sanitization and output escaping on user supplied attributes (such as 'organizer_id', 'widt…
CVE-2026-8899
Auto Thumbnail WordPress Plugin Stored XSS via Shortcode Attributes
00:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on the shortcode's 'width' and 'height' attributes in …
CVE-2026-9022
The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in
10:48 KSA
MEDIUM
CVSS 6.4
CWE-79
The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c…
CVE-2026-9342
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an un
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. …
CVE-2026-9347
A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /gofo
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of the argument ip/mask/gateway leads to os command injection. It is possible to initiate the attack re…
CVE-2026-9359
A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of t
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanS…
CVE-2026-9361
A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formA
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Handler. This manipulation of the argument submit-url causes command injection. The attack may be initiated remotely. The exp…
CVE-2026-9362
A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnec
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the component Setting Handler. Such manipulation of the argument max_Conn/timeOut leads to command inje…
CVE-2026-9363
A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Request Handler. Performing a manipulation of the argument method results in command injection. Remote exploitati…
CVE-2026-9533
Totolik CA750-PoE OS Command Injection in Firmware Upgrade Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is pos…
CVE-2026-9498
Dromara lamp-cloud Template Injection in Message Template Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-791
A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in…
CVE-2026-9511
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attac…
CVE-2026-9512
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordC
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection.…
CVE-2026-9513
Totolik CA750-PoE OS Command Injection in NTP Sync Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be…
CVE-2026-9514
Totolink CA750-PoE OS Command Injection in Network Diagnostics Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/Net…
CVE-2026-9515
Totolink CA750-PoE OS Command Injection via plugin_version Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may b…
CVE-2026-9524
SQL Injection in xianrendzw EasyReport REST Endpoint reportParams
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor w…
CVE-2026-9531
Totolink CA750-PoE OS Command Injection via FileName Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried …
CVE-2026-9532
Totolink CA750-PoE OS Command Injection via FileName Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attac…
CVE-2026-9400
Edimax BR-6675nD Command Injection via formUSBStorage POST Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. Executing a manipulation of the argument sub_dir can lead to command injection. It is possible to launch the at…
CVE-2026-9542
CodeAstro Leave Management System SQL Injection in add_staff.php
22:36 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has…
CVE-2026-9579
JeecgBoot Improper Access Control in SysUser Component
05:39 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remot…
CVE-2026-9581
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/co
05:39 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrad…
CVE-2026-9379
Edimax BR-6675nD Command Injection via WPS PIN Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request Handler. This manipulation of the argument pinCode causes command injection. The attack can be initiated remotely. The ex…
CVE-2026-9607
A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of
10:48 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has…
CVE-2026-9378
A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/fo
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument regDomain/ABandregDomain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in command …
CVE-2026-9376
JPress Improper Authorization in Article Submission Endpoint (CVE-2026-9376)
20:16 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. …
CVE-2026-9374
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the
20:16 KSA
MEDIUM
CVSS 6.3
CWE-284
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out…
CVE-2026-9441
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of th
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack…
CVE-2026-9412
SourceCodester Indian Invoicing System 1.0 Improper Access Control
20:16 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly discl…
CVE-2026-9420
KLiK SocialMediaWebsite HTTP GET Parameter Injection Vulnerability
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2026-9424
Edimax EW-7438RPn OS Command Injection in Wireless Configuration
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1…
CVE-2026-9437
DTStack Taier 1.4.0 OS Command Injection via sqlText Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-77
A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to th…
CVE-2026-9411
SQL Injection in SourceCodester Indian Invoicing System Invoice Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer_name/category results in sql…
CVE-2026-9439
Edimax BR-6675nD Command Injection via stainfo Interface Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and…
CVE-2026-9402
Edimax BR-6675nD Command Injection in Wireless Configuration Handler
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argument ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Po…
CVE-2026-9440
Edimax BR-6478AC Command Injection via POST submit-url Parameter
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to laun…
CVE-2026-9497
Fastjson AutoType Deserialization RCE in tcc-transaction
20:16 KSA
MEDIUM
CVSS 6.3
CWE-20
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted …
CVE-2026-9445
SourceCodester Simple POS 1.0 Unrestricted File Upload in addproduct.php
20:16 KSA
MEDIUM
CVSS 6.3
CWE-284
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the a…
CVE-2026-9449
SQL Injection in code-projects Employee Management System 1.0
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be…
CVE-2026-9450
A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been release…
CVE-2026-9451
A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unk
20:16 KSA
MEDIUM
CVSS 6.3
CWE-74
A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. …
CVE-2026-9468
Path Traversal in dazeb cline-mcp-memory-bank handleInitializeMemoryBank
20:16 KSA
MEDIUM
CVSS 6.3
CWE-22
A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleInitializeMemoryBank of the file src/index.ts. The manipulation of the argument projectPath results in path traversal. The…
CVE-2026-9472
Path Traversal in dazeb markdown-downloader File Operations
20:16 KSA
MEDIUM
CVSS 6.3
CWE-22
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be…
CVE-2026-9473
Path Traversal in c-rick jimeng-mcp 1.10.0 File Operations
20:16 KSA
MEDIUM
CVSS 6.3
CWE-22
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initi…
CVE-2026-9483
SourceCodester Student Grades Management System 1.0 Improper Authorization
20:16 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has …
CVE-2026-9484
SourceCodester Student Grades Management System Improper Authorization
20:16 KSA
MEDIUM
CVSS 6.3
CWE-266
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to impro…
CVE-2018-25367
NASA openVSP 3.16.1 Buffer Overflow in Geometry Name Field
20:16 KSA
MEDIUM
CVSS 6.2
CWE-120
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field…
CVE-2018-25369
Visual Ping 0.8.0.0 Buffer Overflow in Input Field Handling
20:16 KSA
MEDIUM
CVSS 6.2
CWE-120
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious payloads exceeding 4108 bytes into the Host, Time Out, Packet Size, Pause, or Loop…
CVE-2018-25378
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp
20:16 KSA
MEDIUM
CVSS 6.2
CWE-789
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content int…
CVE-2026-2237
Synology Storage Manager Sensitive Data Exposure via GET Query Strings
21:16 KSA
MEDIUM
CVSS 6.2
CWE-598
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local attackers to obtain sensitive information.