CVE-2026-81644
Last Modified: 10 Sept 2026DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49312
Last Modified: 10 Sept 2026Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49310
Last Modified: 10 Sept 2026Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49314
Last Modified: 10 Sept 2026OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49311
Last Modified: 10 Sept 2026Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-13709
Last Modified: 9 Sept 2026The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-15667
Last Modified: 9 Sept 2026The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
CVE-2026-15406
Last Modified: 9 Sept 2026The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2026-76801
Last Modified: 9 Sept 2026The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_contents, combined with no sanitization of PHP condition rule values stored via the firebox_meta REST endpoint. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. On sites upgraded from a version prior to 3.1.10, the Migrator::preserveCampaignRoleAccess() function automatically grants the edit_fireboxes and publish_fireboxes capabilities to the Author role, lowering the effective entry point to Author-level access.
CVE-2026-13359
Last Modified: 10 Sept 2026The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload executes in the context of an administrator's browser session when they visit the plugin's message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, making it possible to compromise administrator-level sessions via a simple unauthenticated contact form submission.
CVE-2026-12956
Last Modified: 9 Sept 2026The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory.
CVE-2026-87036
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87021
Last Modified: 10 Sept 2026Tanium addressed an unauthorized code execution vulnerability in Comply.
CVE-2026-87023
Last Modified: 11 Sept 2026Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87084
Last Modified: 10 Sept 2026Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-87048
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87034
Last Modified: 10 Sept 2026Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87073
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87032
Last Modified: 10 Sept 2026Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-87072
Last Modified: 11 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035
Last Modified: 10 Sept 2026Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-87033
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-14892
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2026-87030
Last Modified: 10 Sept 2026Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87046
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87025
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87075
Last Modified: 11 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87019
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-14505
Last Modified: 9 Sept 2026Tanium addressed a path traversal vulnerability in Tanium Data Service.
CVE-2026-87037
Last Modified: 10 Sept 2026Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87088
Last Modified: 10 Sept 2026Tanium addressed an unauthorized code execution vulnerability in Enforce.
CVE-2026-87724
Last Modified: 10 Sept 2026Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
CVE-2026-87083
Last Modified: 9 Sept 2026A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.
CVE-2026-87593
Last Modified: 9 Sept 2026Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87430
Last Modified: 9 Sept 2026Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87544
Last Modified: 10 Sept 2026Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87601
Last Modified: 9 Sept 2026Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87602
Last Modified: 9 Sept 2026Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87437
Last Modified: 9 Sept 2026Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87608
Last Modified: 11 Sept 2026Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87551
Last Modified: 10 Sept 2026Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87477
Last Modified: 9 Sept 2026Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87571
Last Modified: 10 Sept 2026Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87575
Last Modified: 10 Sept 2026Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87489
Last Modified: 9 Sept 2026Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-87469
Last Modified: 11 Sept 2026Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
CVE-2026-87631
Last Modified: 9 Sept 2026Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87461
Last Modified: 9 Sept 2026Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-87473
Last Modified: 10 Sept 2026Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
