CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2026-21108

    Last Modified: 10 Sept 2026

    Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

    Published: 9 Sept 2026
    6.9
    Medium

    CVE-2026-21107

    Last Modified: 10 Sept 2026

    Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    5.1
    Medium

    CVE-2026-21106

    Last Modified: 11 Sept 2026

    Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

    Published: 9 Sept 2026
    5.9
    Medium

    CVE-2026-21105

    Last Modified: 10 Sept 2026

    Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.

    Published: 9 Sept 2026
    7.1
    High

    CVE-2026-21104

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 9 Sept 2026
    6.8
    Medium

    CVE-2026-21103

    Last Modified: 11 Sept 2026

    Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

    Published: 9 Sept 2026
    9.3
    Critical

    CVE-2026-21102

    Last Modified: 10 Sept 2026

    Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

    Published: 9 Sept 2026
    8.4
    High

    CVE-2026-21101

    Last Modified: 11 Sept 2026

    Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

    Published: 9 Sept 2026
    6.9
    Medium

    CVE-2026-21100

    Last Modified: 10 Sept 2026

    Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

    Published: 9 Sept 2026
    5.1
    Medium

    CVE-2026-21099

    Last Modified: 11 Sept 2026

    Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

    Published: 9 Sept 2026
    6.9
    Medium

    CVE-2026-21098

    Last Modified: 10 Sept 2026

    Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.

    Published: 9 Sept 2026
    4.6
    Medium

    CVE-2026-21097

    Last Modified: 10 Sept 2026

    Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

    Published: 9 Sept 2026
    9.2
    Critical

    CVE-2026-21096

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

    Published: 9 Sept 2026
    9.2
    Critical

    CVE-2026-21095

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

    Published: 9 Sept 2026
    6.1
    Medium

    CVE-2026-21094

    Last Modified: 11 Sept 2026

    Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    5.6
    Medium

    CVE-2026-21093

    Last Modified: 11 Sept 2026

    Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    8.8
    High

    CVE-2026-21092

    Last Modified: 11 Sept 2026

    Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

    Published: 9 Sept 2026
    4.8
    Medium

    CVE-2026-21091

    Last Modified: 11 Sept 2026

    Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    4.8
    Medium

    CVE-2026-21090

    Last Modified: 11 Sept 2026

    Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    6.9
    Medium

    CVE-2026-21089

    Last Modified: 11 Sept 2026

    Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    6.9
    Medium

    CVE-2026-21088

    Last Modified: 11 Sept 2026

    Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    8.6
    High

    CVE-2026-21087

    Last Modified: 11 Sept 2026

    Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

    Published: 9 Sept 2026
    4.8
    Medium

    CVE-2026-21086

    Last Modified: 10 Sept 2026

    Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

    Published: 9 Sept 2026
    8.4
    High

    CVE-2026-21085

    Last Modified: 10 Sept 2026

    Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 9 Sept 2026
    5.4
    Medium

    CVE-2026-11821

    Last Modified: 9 Sept 2026

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators.

    Published: 9 Sept 2026
    6.4
    Medium

    CVE-2026-19945

    Last Modified: 10 Sept 2026

    The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An administrator viewing any user's profile via the ?show_user_id= parameter will render the attacker's stored payload in the admin's browser session, enabling cross-privilege script execution.

    Published: 9 Sept 2026
    5.9
    Medium

    CVE-2026-87737

    Last Modified: 9 Sept 2026

    An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87736

    Last Modified: 9 Sept 2026

    An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

    Published: 9 Sept 2026
    4.3
    Medium

    CVE-2026-87735

    Last Modified: 10 Sept 2026

    An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

    Published: 9 Sept 2026
    7.5
    High

    CVE-2026-87734

    Last Modified: 9 Sept 2026

    An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

    Published: 9 Sept 2026
    6.2
    Medium

    CVE-2026-87733

    Last Modified: 9 Sept 2026

    An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

    Published: 9 Sept 2026
    6.2
    Medium

    CVE-2026-87732

    Last Modified: 9 Sept 2026

    An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.

    Published: 9 Sept 2026
    5.5
    Medium

    CVE-2026-49313

    Last Modified: 10 Sept 2026

    Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Sept 2026
    4.8
    Medium

    CVE-2026-49309

    Last Modified: 10 Sept 2026

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Sept 2026
    8.2
    High

    CVE-2026-12855

    Last Modified: 10 Sept 2026

    Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

    Published: 9 Sept 2026
    6.2
    Medium

    CVE-2026-41987

    Last Modified: 10 Sept 2026

    Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 9 Sept 2026
    8.2
    High

    CVE-2026-6485

    Last Modified: 10 Sept 2026

    UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

    Published: 9 Sept 2026
    7.1
    High

    CVE-2026-49315

    Last Modified: 10 Sept 2026

    DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 9 Sept 2026
    5.3
    Medium

    CVE-2026-81647

    Last Modified: 10 Sept 2026

    Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 9 Sept 2026
    5.9
    Medium

    CVE-2026-81646

    Last Modified: 10 Sept 2026

    Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 9 Sept 2026
    6.4
    Medium

    CVE-2026-75966

    Last Modified: 9 Sept 2026

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The contributor comment is stored in a plugin-managed custom table, bypassing WordPress core's wp_kses_post filter, and the save_post hook fires without a nonce check, meaning any user who can edit posts can exploit this without further preconditions.

    Published: 9 Sept 2026
    6.6
    Medium

    CVE-2026-11363

    Last Modified: 10 Sept 2026

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself.

    Published: 9 Sept 2026
    4.9
    Medium

    CVE-2026-19944

    Last Modified: 10 Sept 2026

    The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Shop Manager writes the malicious payload once via the WooCommerce REST products endpoint (POST/PUT /wp-json/wc/v3/products/{id}), and the injected query executes on every subsequent public page view that renders the campaign rewards sidebar.

    Published: 9 Sept 2026
    4.9
    Medium

    CVE-2026-19800

    Last Modified: 10 Sept 2026

    The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The $wpdb->prepare() call does not protect against this injection because the attacker-controlled $contact_filter_query fragment is concatenated into the SQL format string before prepare() executes — prepare() only processes %s/%d placeholders and cannot sanitize content already embedded in the format string. REST API JSON bodies are parsed from php://input and bypass WordPress's wp_magic_quotes(), meaning double-quote characters in status array values reach the SQL sink unescaped. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required 'mint_read_contacts' capability is a plugin-specific capability not assigned to any default WordPress role; it must be explicitly granted by an administrator, making this effectively an Administrator+ vulnerability.

    Published: 9 Sept 2026
    6.1
    Medium

    CVE-2026-19797

    Last Modified: 10 Sept 2026

    The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 9 Sept 2026
    6.4
    Medium

    CVE-2026-77187

    Last Modified: 10 Sept 2026

    The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Sept 2026
    6.4
    Medium

    CVE-2026-77186

    Last Modified: 10 Sept 2026

    The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass relies on hex-encoded shortcode attribute payloads (e.g. \x3cscript\x3e), which wp_kses_post cannot strip on save because they appear as literal backslash sequences rather than real HTML tags; WordPress core's shortcode_parse_atts() then calls stripcslashes() at render time, decoding the escapes into real angle brackets before they reach the unescaped sink.

    Published: 9 Sept 2026
    7.2
    High

    CVE-2026-84293

    Last Modified: 9 Sept 2026

    The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only affects multi-input sub-field types within a repeater (such as Name, Address, and Checkbox fields), as scalar single-input field values are escaped with esc_html() at the output stage in version 3.0.4.

    Published: 9 Sept 2026
    6.1
    Medium

    CVE-2026-7804

    Last Modified: 10 Sept 2026

    The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the crafted request to target a page where a filter using the vulnerable recalculation output is present.

    Published: 9 Sept 2026
    7.2
    High

    CVE-2026-17553

    Last Modified: 10 Sept 2026

    The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec_manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default_role='administrator' and users_can_register='1', then self-registering a new account that is assigned the administrator role.

    Published: 9 Sept 2026
    Items Per Page