CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2026-15431

    Last Modified: 3 Sept 2026

    A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

    Published: 3 Sept 2026
    3.1
    Low

    CVE-2026-49456

    Last Modified: 4 Sept 2026

    Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged into the HTTP Location response header with no URL validation, scheme restriction, or path-only enforcement. Any application that passes user-controlled input to this helper — the natural pattern documented in the JSDoc and official fixtures — is vulnerable to open redirect attacks. An attacker who convinces a victim to click a crafted link can silently redirect the browser to an arbitrary external domain, enabling phishing, credential harvesting, and OAuth token theft. Additionally, scheme-relative URLs (//evil.example/) bypass naive https?://-only allow-list filters that developers might add as ad-hoc mitigations. This issue has been patched in version 1.0.0-beta.1.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-49455

    Last Modified: 4 Sept 2026

    Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated POST to a registered server action endpoint using a CORS-safelisted content type (text/plain), which does not trigger a preflight. Any state-mutating server action that the application exposes via 'use server' can be invoked with the victim's cookies attached. This issue has been patched in version 1.0.0-beta.1.

    Published: 3 Sept 2026
    9.3
    Critical

    CVE-2026-82526

    Last Modified: 4 Sept 2026

    R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.

    Published: 3 Sept 2026
    7.3
    High

    CVE-2026-85028

    Last Modified: 3 Sept 2026

    Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.

    Published: 3 Sept 2026
    5.1
    Medium

    CVE-2026-82024

    Last Modified: 3 Sept 2026

    LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-82023

    Last Modified: 5 Sept 2026

    LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

    Published: 3 Sept 2026
    7.8
    High

    CVE-2026-83959

    Last Modified: 8 Sept 2026

    Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 3 Sept 2026
    5.5
    Medium

    CVE-2026-85187

    Last Modified: 4 Sept 2026

    A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 3 Sept 2026
    8.6
    High

    CVE-2026-63219

    Last Modified: 4 Sept 2026

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

    Published: 3 Sept 2026
    8.5
    High

    CVE-2026-85012

    Last Modified: 4 Sept 2026

    Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.

    Published: 3 Sept 2026
    9.1
    Critical

    CVE-2026-58400

    Last Modified: 4 Sept 2026

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

    Published: 3 Sept 2026
    6.9
    Medium

    CVE-2026-84968

    Last Modified: 10 Sept 2026

    An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

    Published: 3 Sept 2026
    2.1
    Low

    CVE-2026-85186

    Last Modified: 4 Sept 2026

    A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-85304

    Last Modified: 3 Sept 2026

    Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-85309

    Last Modified: 5 Sept 2026

    Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-85308

    Last Modified: 7 Sept 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-85307

    Last Modified: 4 Sept 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-75602

    Last Modified: 5 Sept 2026

    OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temporary filename comes from the attacker-controlled Content-Disposition header, is passed from parseFilenameFromContentDisposition in internal/offline_download/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/client.go, and is opened with os.Create without a containment check. Because filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDownload on any path can traverse out of task.TempDir and create, truncate, or overwrite any file writable by the OpenList process whose parent directory already exists. The server/handles/offline_download.go AddOfflineDownload route uses normal user authentication rather than AuthAdmin, and local-storage destinations fall through tryPutUrl in internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version 4.2.3.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-85306

    Last Modified: 4 Sept 2026

    Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.

    Published: 3 Sept 2026
    5.4
    Medium

    CVE-2026-85305

    Last Modified: 5 Sept 2026

    Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-85303

    Last Modified: 7 Sept 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-85302

    Last Modified: 7 Sept 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84848

    Last Modified: 4 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

    Published: 3 Sept 2026
    7.5
    High

    CVE-2026-84847

    Last Modified: 5 Sept 2026

    Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84836

    Last Modified: 4 Sept 2026

    Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

    Published: 3 Sept 2026
    9.8
    Critical

    CVE-2026-84834

    Last Modified: 7 Sept 2026

    Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

    Published: 3 Sept 2026
    9.8
    Critical

    CVE-2026-84814

    Last Modified: 3 Sept 2026

    Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

    Published: 3 Sept 2026
    9.3
    Critical

    CVE-2026-84813

    Last Modified: 4 Sept 2026

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84812

    Last Modified: 7 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

    Published: 3 Sept 2026
    8.1
    High

    CVE-2026-84779

    Last Modified: 4 Sept 2026

    Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

    Published: 3 Sept 2026
    7.5
    High

    CVE-2026-84778

    Last Modified: 7 Sept 2026

    Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

    Published: 3 Sept 2026
    7.4
    High

    CVE-2026-84777

    Last Modified: 3 Sept 2026

    Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

    Published: 3 Sept 2026
    7.5
    High

    CVE-2026-84776

    Last Modified: 4 Sept 2026

    Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

    Published: 3 Sept 2026
    6.1
    Medium

    CVE-2026-84774

    Last Modified: 5 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

    Published: 3 Sept 2026
    7.2
    High

    CVE-2026-84773

    Last Modified: 4 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-84769

    Last Modified: 7 Sept 2026

    Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

    Published: 3 Sept 2026
    9.3
    Critical

    CVE-2026-84768

    Last Modified: 3 Sept 2026

    Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-84767

    Last Modified: 4 Sept 2026

    Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.

    Published: 3 Sept 2026
    5.9
    Medium

    CVE-2026-84766

    Last Modified: 7 Sept 2026

    Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84765

    Last Modified: 4 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84763

    Last Modified: 7 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

    Published: 3 Sept 2026
    5.3
    Medium

    CVE-2026-84762

    Last Modified: 3 Sept 2026

    Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

    Published: 3 Sept 2026
    7.2
    High

    CVE-2026-84761

    Last Modified: 4 Sept 2026

    Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-84758

    Last Modified: 7 Sept 2026

    Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.

    Published: 3 Sept 2026
    8.2
    High

    CVE-2026-84757

    Last Modified: 3 Sept 2026

    Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

    Published: 3 Sept 2026
    7.1
    High

    CVE-2026-84756

    Last Modified: 7 Sept 2026

    Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-84755

    Last Modified: 7 Sept 2026

    Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.

    Published: 3 Sept 2026
    6.5
    Medium

    CVE-2026-84754

    Last Modified: 7 Sept 2026

    Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.

    Published: 3 Sept 2026
    9.8
    Critical

    CVE-2026-84753

    Last Modified: 7 Sept 2026

    Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

    Published: 3 Sept 2026
    Items Per Page