CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2026-77538

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.

    Published: 26 Aug 2026
    10
    Critical

    CVE-2026-77537

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77536

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-18794

    Last Modified: 28 Aug 2026

    The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

    Published: 26 Aug 2026
    6.4
    Medium

    CVE-2026-2388

    Last Modified: 28 Aug 2026

    The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding untrusted vicinity content inside those tags. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Aug 2026
    9.1
    Critical

    CVE-2026-77535

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.

    Published: 26 Aug 2026
    9.3
    Critical

    CVE-2026-59683

    Last Modified: 28 Aug 2026

    The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context).

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77534

    Last Modified: 26 Aug 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-19042

    Last Modified: 26 Aug 2026

    A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-59682

    Last Modified: 28 Aug 2026

    Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-16444

    Last Modified: 28 Aug 2026

    Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.

    Published: 26 Aug 2026
    9.9
    Critical

    CVE-2026-77533

    Last Modified: 1 Sept 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

    Published: 26 Aug 2026
    6.3
    Medium

    CVE-2026-19197

    Last Modified: 1 Sept 2026

    A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

    Published: 26 Aug 2026
    8.2
    High

    CVE-2026-19538

    Last Modified: 8 Sept 2026

    The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

    Published: 26 Aug 2026
    8.2
    High

    CVE-2026-19401

    Last Modified: 8 Sept 2026

    Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.

    Published: 26 Aug 2026
    6.9
    Medium

    CVE-2026-18916

    Last Modified: 8 Sept 2026

    Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

    Published: 26 Aug 2026
    8.2
    High

    CVE-2026-18664

    Last Modified: 8 Sept 2026

    When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the comparison is done in 4 times a unsigned 32 bit number comparison, again with the endianness of the host where all values are actually in network bye order.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-80237

    Last Modified: 28 Aug 2026

    EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-80236

    Last Modified: 28 Aug 2026

    Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.

    Published: 26 Aug 2026
    9.3
    Critical

    CVE-2026-80235

    Last Modified: 28 Aug 2026

    EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published: 26 Aug 2026
    6.9
    Medium

    CVE-2026-80234

    Last Modified: 28 Aug 2026

    CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.

    Published: 26 Aug 2026
    8.6
    High

    CVE-2026-80233

    Last Modified: 28 Aug 2026

    CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.

    Published: 26 Aug 2026
    6.3
    Medium

    CVE-2026-9668

    Last Modified: 1 Sept 2026

    With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently lead to slow database queries and expanded query coverage. This vulnerability features a low exploitation threshold, wide scope of impact, requires no external privilege escalation, and is classified as a high-priority fix.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-75977

    Last Modified: 26 Aug 2026

    The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.

    Published: 26 Aug 2026
    6.4
    Medium

    CVE-2026-6178

    Last Modified: 26 Aug 2026

    The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-18884

    Last Modified: 28 Aug 2026

    The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 26 Aug 2026
    7.8
    High

    CVE-2026-78237

    Last Modified: 28 Aug 2026

    Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.

    Published: 26 Aug 2026
    8.8
    High

    CVE-2026-78236

    Last Modified: 28 Aug 2026

    An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

    Published: 26 Aug 2026
    1.2
    Low

    CVE-2026-58108

    Last Modified: 26 Aug 2026

    The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an implicit cross join, so the filter does not constrain the delete to the calling user's own token in the way the code reads as intending. This way a user can delete all personal access tokens in the system.

    Published: 26 Aug 2026
    2.4
    Low

    CVE-2026-15366

    Last Modified: 28 Aug 2026

    A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page

    Published: 26 Aug 2026
    2.4
    Low

    CVE-2026-15365

    Last Modified: 28 Aug 2026

    A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app.

    Published: 26 Aug 2026
    7.2
    High

    CVE-2026-18331

    Last Modified: 28 Aug 2026

    The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By forging frm_user_id to match an administrator's user ID — discoverable via the public WordPress REST API — an unauthenticated attacker causes wp_kses_post() to serve as the only output filter, which preserves the injected payload structurally intact; the plugin's admin JavaScript then decodes and executes it automatically on page load.

    Published: 26 Aug 2026
    9.8
    Critical

    CVE-2026-18431

    Last Modified: 1 Sept 2026

    The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.

    Published: 26 Aug 2026
    6.4
    Medium

    CVE-2026-3002

    Last Modified: 26 Aug 2026

    The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Aug 2026
    6.5
    Medium

    CVE-2026-78146

    Last Modified: 26 Aug 2026

    The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.

    Published: 26 Aug 2026
    5.5
    Medium

    CVE-2026-77790

    Last Modified: 3 Sept 2026

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

    Published: 26 Aug 2026
    4.3
    Medium

    CVE-2026-77789

    Last Modified: 26 Aug 2026

    The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-77758

    Last Modified: 26 Aug 2026

    The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.

    Published: 26 Aug 2026
    5.4
    Medium

    CVE-2026-77757

    Last Modified: 26 Aug 2026

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly accessible directory, and to delete them from their original location.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-77754

    Last Modified: 26 Aug 2026

    The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.

    Published: 26 Aug 2026
    6.5
    Medium

    CVE-2026-77695

    Last Modified: 26 Aug 2026

    The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return requests on any guest order.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-77694

    Last Modified: 26 Aug 2026

    The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.

    Published: 26 Aug 2026
    8.7
    High

    CVE-2026-77693

    Last Modified: 26 Aug 2026

    The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.

    Published: 26 Aug 2026
    5.3
    Medium

    CVE-2026-75798

    Last Modified: 1 Sept 2026

    The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.

    Published: 26 Aug 2026
    7.7
    High

    CVE-2026-75797

    Last Modified: 1 Sept 2026

    The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

    Published: 26 Aug 2026
    4.3
    Medium

    CVE-2026-74930

    Last Modified: 26 Aug 2026

    The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details of projects they have no access to.

    Published: 26 Aug 2026
    5.4
    Medium

    CVE-2026-74929

    Last Modified: 26 Aug 2026

    The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.

    Published: 26 Aug 2026
    7.5
    High

    CVE-2026-74928

    Last Modified: 26 Aug 2026

    The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.

    Published: 26 Aug 2026
    7.2
    High

    CVE-2026-74851

    Last Modified: 26 Aug 2026

    The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

    Published: 26 Aug 2026
    8.1
    High

    CVE-2026-19718

    Last Modified: 26 Aug 2026

    The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.

    Published: 26 Aug 2026