CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-81781

    Last Modified: 8 Sept 2026

    Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-81790

    Last Modified: 8 Sept 2026

    Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

    Published: 8 Sept 2026
    7.1
    High

    CVE-2026-81798

    Last Modified: 8 Sept 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.

    Published: 8 Sept 2026
    7.1
    High

    CVE-2026-84818

    Last Modified: 8 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

    Published: 8 Sept 2026
    7.1
    High

    CVE-2026-84817

    Last Modified: 8 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-81802

    Last Modified: 8 Sept 2026

    Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-81792

    Last Modified: 8 Sept 2026

    Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

    Published: 8 Sept 2026
    7.1
    High

    CVE-2026-84820

    Last Modified: 8 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86519

    Last Modified: 11 Sept 2026

    A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86518

    Last Modified: 8 Sept 2026

    A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86517

    Last Modified: 9 Sept 2026

    A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 8 Sept 2026
    5.1
    Medium

    CVE-2026-86516

    Last Modified: 8 Sept 2026

    A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86515

    Last Modified: 8 Sept 2026

    A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a143e. It is advisable to implement a patch to correct this issue.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86514

    Last Modified: 11 Sept 2026

    A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86513

    Last Modified: 8 Sept 2026

    A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86512

    Last Modified: 9 Sept 2026

    A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    7.7
    High

    CVE-2026-19397

    Last Modified: 8 Sept 2026

    Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the '  Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.3
    Medium

    CVE-2026-12962

    Last Modified: 8 Sept 2026

    A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.7
    Medium

    CVE-2026-18023

    Last Modified: 9 Sept 2026

    Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    2
    Low

    CVE-2026-16003

    Last Modified: 9 Sept 2026

    Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.9
    Medium

    CVE-2026-16004

    Last Modified: 8 Sept 2026

    Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.8
    Medium

    CVE-2026-16005

    Last Modified: 8 Sept 2026

    Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.7
    Medium

    CVE-2026-16006

    Last Modified: 9 Sept 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.7
    Medium

    CVE-2026-75808

    Last Modified: 8 Sept 2026

    Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.9
    Medium

    CVE-2026-75809

    Last Modified: 8 Sept 2026

    Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.7
    Medium

    CVE-2026-75810

    Last Modified: 8 Sept 2026

    Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86511

    Last Modified: 8 Sept 2026

    A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    5.8
    Medium

    CVE-2026-75811

    Last Modified: 8 Sept 2026

    Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-86510

    Last Modified: 8 Sept 2026

    A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-86509

    Last Modified: 11 Sept 2026

    A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.

    Published: 8 Sept 2026
    2.3
    Low

    CVE-2026-82710

    Last Modified: 8 Sept 2026

    Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which indexes the documentation of every published package, and prints the matching results (title, package, type, doc reference, and highlighted snippets) to the terminal. The formatter in Mix.Tasks.UsageRules.SearchDocs interpolated those publisher-controlled fields verbatim, neutralizing no terminal control characters; the only transform it applied adds escape sequences rather than removing them. A malicious package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns, OSC 52 clipboard writes) in its indexed documentation, so when a developer runs a search that surfaces those docs the sequences reach the terminal unchanged — forging the displayed hexdocs URL or a suggested command, hiding text, or writing to the clipboard. No authentication or privileged position is required; only publishing a package. This issue affects usage_rules: from 0.1.18 before 1.2.8.

    Published: 8 Sept 2026
    4.3
    Medium

    CVE-2026-76977

    Last Modified: 8 Sept 2026

    SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-76971

    Last Modified: 8 Sept 2026

    Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.

    Published: 8 Sept 2026
    9.4
    Critical

    CVE-2026-76969

    Last Modified: 8 Sept 2026

    @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-76968

    Last Modified: 8 Sept 2026

    SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-76967

    Last Modified: 8 Sept 2026

    SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.

    Published: 8 Sept 2026
    4.3
    Medium

    CVE-2026-76963

    Last Modified: 8 Sept 2026

    Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.

    Published: 8 Sept 2026
    4.3
    Medium

    CVE-2026-76962

    Last Modified: 8 Sept 2026

    SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

    Published: 8 Sept 2026
    3.5
    Low

    CVE-2026-76961

    Last Modified: 9 Sept 2026

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

    Published: 8 Sept 2026
    3.5
    Low

    CVE-2026-76960

    Last Modified: 8 Sept 2026

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

    Published: 8 Sept 2026
    4.6
    Medium

    CVE-2026-76959

    Last Modified: 8 Sept 2026

    SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.

    Published: 8 Sept 2026
    8.5
    High

    CVE-2026-76958

    Last Modified: 8 Sept 2026

    SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.

    Published: 8 Sept 2026
    9
    Critical

    CVE-2026-66768

    Last Modified: 8 Sept 2026

    SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.

    Published: 8 Sept 2026
    7.7
    High

    CVE-2026-66767

    Last Modified: 8 Sept 2026

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-58240

    Last Modified: 8 Sept 2026

    SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.

    Published: 8 Sept 2026
    2.2
    Low

    CVE-2026-58234

    Last Modified: 8 Sept 2026

    SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-44766

    Last Modified: 8 Sept 2026

    SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-44756

    Last Modified: 8 Sept 2026

    A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-78838

    Last Modified: 10 Sept 2026

    A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-78837

    Last Modified: 10 Sept 2026

    A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

    Published: 8 Sept 2026
    Items Per Page