CVE-2026-15431
Last Modified: 3 Sept 2026A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
CVE-2026-49456
Last Modified: 4 Sept 2026Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged into the HTTP Location response header with no URL validation, scheme restriction, or path-only enforcement. Any application that passes user-controlled input to this helper — the natural pattern documented in the JSDoc and official fixtures — is vulnerable to open redirect attacks. An attacker who convinces a victim to click a crafted link can silently redirect the browser to an arbitrary external domain, enabling phishing, credential harvesting, and OAuth token theft. Additionally, scheme-relative URLs (//evil.example/) bypass naive https?://-only allow-list filters that developers might add as ad-hoc mitigations. This issue has been patched in version 1.0.0-beta.1.
CVE-2026-49455
Last Modified: 4 Sept 2026Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated POST to a registered server action endpoint using a CORS-safelisted content type (text/plain), which does not trigger a preflight. Any state-mutating server action that the application exposes via 'use server' can be invoked with the victim's cookies attached. This issue has been patched in version 1.0.0-beta.1.
CVE-2026-82526
Last Modified: 4 Sept 2026R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.
CVE-2026-85028
Last Modified: 3 Sept 2026Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.
CVE-2026-82024
Last Modified: 3 Sept 2026LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.
CVE-2026-82023
Last Modified: 5 Sept 2026LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
CVE-2026-83959
Last Modified: 8 Sept 2026Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-85187
Last Modified: 4 Sept 2026A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-63219
Last Modified: 4 Sept 2026GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
CVE-2026-85012
Last Modified: 4 Sept 2026Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.
CVE-2026-58400
Last Modified: 4 Sept 2026GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
CVE-2026-84968
Last Modified: 10 Sept 2026An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.
CVE-2026-85186
Last Modified: 4 Sept 2026A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-85304
Last Modified: 3 Sept 2026Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
CVE-2026-85309
Last Modified: 5 Sept 2026Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
CVE-2026-85308
Last Modified: 7 Sept 2026Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.
CVE-2026-85307
Last Modified: 4 Sept 2026Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.
CVE-2026-75602
Last Modified: 5 Sept 2026OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temporary filename comes from the attacker-controlled Content-Disposition header, is passed from parseFilenameFromContentDisposition in internal/offline_download/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/client.go, and is opened with os.Create without a containment check. Because filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDownload on any path can traverse out of task.TempDir and create, truncate, or overwrite any file writable by the OpenList process whose parent directory already exists. The server/handles/offline_download.go AddOfflineDownload route uses normal user authentication rather than AuthAdmin, and local-storage destinations fall through tryPutUrl in internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version 4.2.3.
CVE-2026-85306
Last Modified: 4 Sept 2026Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.
CVE-2026-85305
Last Modified: 5 Sept 2026Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
CVE-2026-85303
Last Modified: 7 Sept 2026Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
CVE-2026-85302
Last Modified: 7 Sept 2026Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.
CVE-2026-84848
Last Modified: 4 Sept 2026Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
CVE-2026-84847
Last Modified: 5 Sept 2026Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
CVE-2026-84836
Last Modified: 4 Sept 2026Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
CVE-2026-84834
Last Modified: 7 Sept 2026Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84814
Last Modified: 3 Sept 2026Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84813
Last Modified: 4 Sept 2026Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84812
Last Modified: 7 Sept 2026Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-84779
Last Modified: 4 Sept 2026Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.
CVE-2026-84778
Last Modified: 7 Sept 2026Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.
CVE-2026-84777
Last Modified: 3 Sept 2026Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
CVE-2026-84776
Last Modified: 4 Sept 2026Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
CVE-2026-84774
Last Modified: 5 Sept 2026Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84773
Last Modified: 4 Sept 2026Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
CVE-2026-84769
Last Modified: 7 Sept 2026Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
CVE-2026-84768
Last Modified: 3 Sept 2026Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-84767
Last Modified: 4 Sept 2026Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
CVE-2026-84766
Last Modified: 7 Sept 2026Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84765
Last Modified: 4 Sept 2026Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
CVE-2026-84763
Last Modified: 7 Sept 2026Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
CVE-2026-84762
Last Modified: 3 Sept 2026Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84761
Last Modified: 4 Sept 2026Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
CVE-2026-84758
Last Modified: 7 Sept 2026Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84757
Last Modified: 3 Sept 2026Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
CVE-2026-84756
Last Modified: 7 Sept 2026Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
CVE-2026-84755
Last Modified: 7 Sept 2026Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-84754
Last Modified: 7 Sept 2026Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-84753
Last Modified: 7 Sept 2026Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
