CVE-2026-66641
Last Modified: 24 Aug 2026Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
CVE-2026-66640
Last Modified: 21 Aug 2026Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
CVE-2026-66639
Last Modified: 21 Aug 2026Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
CVE-2026-66638
Last Modified: 24 Aug 2026Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66637
Last Modified: 18 Aug 2026Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
CVE-2026-66636
Last Modified: 24 Aug 2026Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
CVE-2026-66635
Last Modified: 24 Aug 2026Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
CVE-2026-66634
Last Modified: 21 Aug 2026Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
CVE-2026-66633
Last Modified: 21 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
CVE-2026-66629
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
CVE-2026-66627
Last Modified: 7 Sept 2026Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.
CVE-2026-66622
Last Modified: 18 Aug 2026Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
CVE-2026-66621
Last Modified: 25 Aug 2026Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.
CVE-2026-66620
Last Modified: 21 Aug 2026Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
CVE-2026-32553
Last Modified: 18 Aug 2026Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVE-2026-32549
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
CVE-2026-32547
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
CVE-2026-32481
Last Modified: 18 Aug 2026Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
CVE-2026-32474
Last Modified: 21 Aug 2026Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-32473
Last Modified: 21 Aug 2026Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
CVE-2026-32472
Last Modified: 21 Aug 2026Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
CVE-2026-32470
Last Modified: 18 Aug 2026Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-32468
Last Modified: 24 Aug 2026Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
CVE-2026-32467
Last Modified: 21 Aug 2026Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
CVE-2026-32466
Last Modified: 21 Aug 2026Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
CVE-2026-32465
Last Modified: 18 Aug 2026Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
CVE-2026-32464
Last Modified: 21 Aug 2026Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
CVE-2026-32463
Last Modified: 21 Aug 2026Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-32444
Last Modified: 21 Aug 2026Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32333
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
CVE-2026-28571
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
CVE-2026-28570
Last Modified: 21 Aug 2026Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
CVE-2026-28569
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
CVE-2026-28568
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-28567
Last Modified: 21 Aug 2026Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
CVE-2026-28192
Last Modified: 24 Aug 2026Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CVE-2026-28191
Last Modified: 1 Sept 2026Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-17084
Last Modified: 10 Sept 2026The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.
CVE-2026-75890
Last Modified: 18 Aug 2026Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.
CVE-2026-73692
Last Modified: 18 Aug 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-50575
Last Modified: 21 Aug 2026BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.
CVE-2026-24301
Last Modified: 10 Sept 2026Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-16309
Last Modified: 21 Aug 2026Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7.
CVE-2026-45532
Last Modified: 18 Aug 2026DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
CVE-2026-75783
Last Modified: 18 Aug 2026A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
CVE-2026-18751
Last Modified: 19 Aug 2026External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
CVE-2026-74989
Last Modified: 1 Sept 2026Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
CVE-2026-74988
Last Modified: 1 Sept 2026Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74986
Last Modified: 25 Aug 2026Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74985
Last Modified: 25 Aug 2026Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
