CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 02.09.2026 9.2
CVE-2026-82955 02.09.2026 9
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026 9.2
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8
CVE-2026-9055 Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' 02.09.2026 9.8
CVE-2026-84695 BookStack before 26.05.4 Stored XSS via Drawing Upload 02.09.2026 9.3
CVE-2026-84696 Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands 02.09.2026 9.3
CVE-2026-84699 Team Password Manager before 14.184.308 Authentication Bypass in Password Reset 02.09.2026 9.3
CVE-2026-84479 WWBN AVideo Authentication Bypass via User-Agent Header 02.09.2026 9.3
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass 01.09.2026 9.3
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter 02.09.2026 9.3
CVE-2026-75604 Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 01.09.2026 9
CVE-2026-84372 Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections 01.09.2026 9.8
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 02.09.2026 9.8
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access 01.09.2026 10
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon 01.09.2026 10
CVE-2026-19766 Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer 02.09.2026 9.6
CVE-2026-73700 Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface 02.09.2026 9
CVE-2026-73701 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer 02.09.2026 9
CVE-2026-79687 02.09.2026 9
CVE-2026-18931 Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software 01.09.2026 9.1
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack 01.09.2026 9.3
CVE-2026-18210 SQL Injection in TRtek Technological Products's Store 01.09.2026 9.8
CVE-2026-9621 RSLinx Classic® - Multiple Vulnerabilities 01.09.2026 9.2
CVE-2026-18808 Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO 01.09.2026 9.8
CVE-2026-18765 SQL Injection in Teracity Sotware's Teracity E-OSB Platform 01.09.2026 9.8
CVE-2026-84149 Information Disclosure Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2026-84147 Remote Code Execution Vulnerability in Manacle Technologies ERP System 01.09.2026 10
CVE-2026-84148 Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites 01.09.2026 9.3
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API 01.09.2026 9.2
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions 01.09.2026 9.4
CVE-2026-18550 Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter 01.09.2026 9.8
CVE-2026-4813 Code injection in the Lutece Core 01.09.2026 9.4
CVE-2026-78319 TOCTOU Vulnerability in file exchange 01.09.2026 9.3
CVE-2026-83772 Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection 01.09.2026 9.4
CVE-2026-67394 01.09.2026 9
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint 01.09.2026 9.8
CVE-2026-83524 RedPort Optimizer wXa-223 System Clock datetime.php exec command injection 01.09.2026 9.4
CVE-2026-82971 QVidium Opera11 CGI Script net_tr.cgi command injection 01.09.2026 10
CVE-2026-82954 Dokploy Settings application.ts writeTraefikConfigInPath path traversal 31.08.2026 9.4
CVE-2026-81779 WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability 01.09.2026 10
CVE-2026-81293 WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81756 WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-81763 WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81780 WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability 01.09.2026 10
CVE-2026-82226 WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability 01.09.2026 9.8
CVE-2026-82908 MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow 01.09.2026 9.3
CVE-2026-53552 Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers 01.09.2026 9.6
CVE-2026-79748 MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) 31.08.2026 9.9
CVE-2026-82807 ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management 01.09.2026 9.3
CVE-2026-73819 Ebyte NA111-M Weak Authentication 01.09.2026 9.3
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 01.09.2026 9.3
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 02.09.2026 9.2
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026 10
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026 10
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026 10
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 02.09.2026 9.4
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 01.09.2026 9.4
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 02.09.2026 9.3
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026 9.3
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026 9.3
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 02.09.2026 9.3
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 01.09.2026 9.3
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026 9.3
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026 9.3
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026 9.3
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026 9.4
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026 9.3
CVE-2026-58574 31.08.2026 9.8
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow 01.09.2026 9.4
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow 01.09.2026 9.4
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow 31.08.2026 9.4
CVE-2026-82645 AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token 31.08.2026 9.2
CVE-2026-82653 SiYuan before v3.8.1 Stored XSS via confirmDialog 30.08.2026 9.3
CVE-2026-82654 SiYuan before v3.8.1 Stored XSS via block name 01.09.2026 9.3
CVE-2026-82542 Tenda HG10 Boa Web Server formIPv6Routing buffer overflow 01.09.2026 10
CVE-2026-82539 TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption 01.09.2026 9.4
CVE-2026-15980 MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token 31.08.2026 9.8
CVE-2026-15369 Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout 01.09.2026 9.8
CVE-2026-82460 Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown 31.08.2026 9.3
CVE-2026-82466 Rodauth before 2.46.0 Authentication Bypass via webauthn_login 31.08.2026 9.4
CVE-2026-82452 rust-iot-platform Authentication Bypass via Missing Request Guards 01.09.2026 9.3
CVE-2026-82454 Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in 31.08.2026 9.3
CVE-2026-82456 argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP 29.08.2026 10
CVE-2026-82448 Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key 31.08.2026 9.3
CVE-2026-14494 Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field 31.08.2026 9.8
CVE-2026-18527 IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. 31.08.2026 9.9
CVE-2026-19286 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 01.09.2026 9.8
CVE-2026-19295 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 01.09.2026 9.9
CVE-2026-3627 Multiple Vulnerabilities in IBM Concert Software 01.09.2026 9.1
CVE-2026-54745 Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true 31.08.2026 10
CVE-2026-54754 Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) 31.08.2026 9.6
CVE-2026-54755 Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) 31.08.2026 9.6
CVE-2026-55068 free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints 31.08.2026 9.3
CVE-2026-55220 Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column 31.08.2026 9.3
CVE-2026-55247 plone.app.event: Denial of service via iCalendar import 31.08.2026 9.1
CVE-2026-55248 plone.app.portlets: Denial of service via RSS feed portlet 28.08.2026 9.1
CVE-2026-55378 JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values 01.09.2026 9.3
CVE-2026-55511 Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` 01.09.2026 9.1
CVE-2026-55559 Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) 28.08.2026 9.8
CVE-2026-55565 Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 31.08.2026 9.9
CVE-2026-55634 Pimcore: Remote Code Execution via DataObject Class-Definition Field Name 28.08.2026 9.9
CVE-2026-82021 Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference 31.08.2026 9
CVE-2026-82266 Redpanda Admin API Unauthenticated Superuser Access via Default Configuration 01.09.2026 9.3
CVE-2026-82277 Argo Rollouts Dashboard Unauthenticated Mutating Operations 31.08.2026 9.3
CVE-2026-82281 Kotaemon Missing Ownership Check in Conversation Functions 31.08.2026 9.1
CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory 31.08.2026 9.8
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 01.09.2026 9.4
CVE-2026-18918 OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default 31.08.2026 9.1
CVE-2026-42007 28.08.2026 9.1
CVE-2026-82222 WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability 28.08.2026 10
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() 28.08.2026 9.4
CVE-2026-40541 28.08.2026 9
CVE-2026-76581 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 28.08.2026 9.8
CVE-2026-78032 28.08.2026 9.3
CVE-2026-80600 batman-adv: dat: acquire ARP hw source only after skb realloc 29.08.2026 9.8
CVE-2026-80603 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read 29.08.2026 9.1
CVE-2026-80609 qede: fix out-of-bounds check for cqe->len_list[] 29.08.2026 9.8
CVE-2026-80612 net: lwtunnel: Drop skb metadata before LWT encapsulation 29.08.2026 9.8
CVE-2026-80617 net: airoha: fix foe_check_time allocation size 29.08.2026 9.8
CVE-2026-80630 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 29.08.2026 9.8
CVE-2026-80634 netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag 29.08.2026 9.8
CVE-2026-80668 netfilter: nf_conntrack_expect: use conntrack GC to reap expectations 29.08.2026 9.8
CVE-2026-80670 perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 29.08.2026 9.1
CVE-2026-80671 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 29.08.2026 9.3
CVE-2026-80673 ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() 29.08.2026 9.8
CVE-2026-80674 ntfs: validate resident attribute lists and harden the validator 29.08.2026 9.8
CVE-2026-80681 vxlan: re-fetch eth header after route_shortcircuit() 29.08.2026 9.8
CVE-2026-80684 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 29.08.2026 9.3
CVE-2026-80693 idpf: bound interrupt-vector register fill to the allocated array 29.08.2026 9.3
CVE-2026-80694 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 29.08.2026 9.8
CVE-2026-80714 ipvs: do not propagate one-packet flag to synced conns 29.08.2026 9.8
CVE-2026-82082 Green-Computing|NUMail - OS Command Injection 31.08.2026 9.3
CVE-2026-82090 28.08.2026 9.2
CVE-2026-13086 Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint 29.08.2026 9.3
CVE-2026-19313 Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution 29.08.2026 9.3
CVE-2026-19315 Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution 01.09.2026 9.3
CVE-2026-19318 Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution 29.08.2026 9.3
CVE-2026-61800 Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) 28.08.2026 9.1
CVE-2026-78174 WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs 28.08.2026 9.3
CVE-2026-18717 Improper Certificate Validation in ASE 2000 28.08.2026 9.1
CVE-2026-50152 Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users 01.09.2026 9.1
CVE-2026-68929 FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization 28.08.2026 9.3
CVE-2026-69658 Ebyte NA111-M Cleartext Transmission of Sensitive Information 31.08.2026 9.3
CVE-2026-71187 Ebyte NA111-M Use of Client-Side Authentication 31.08.2026 9.3
CVE-2026-73125 Ebyte NA111-M Missing Authentication for Critical Function 31.08.2026 9.3
CVE-2026-76179 Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings 31.08.2026 9.3
CVE-2026-76943 Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel 28.08.2026 9.3
CVE-2026-78239 Xiiaozet LK100W Missing Authentication for Critical Function 28.08.2026 9.3
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API 29.08.2026 10
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor 29.08.2026 10
CVE-2026-19092 Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing 28.08.2026 9.8
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client 29.08.2026 9.3
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml 31.08.2026 9.3
CVE-2026-53579 Trilium: Note Import to RCE via Book Note 28.08.2026 9.3
CVE-2026-6876 Sandbox Escape in ServiceNow AI Platform 01.09.2026 10
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause 29.08.2026 10
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 27.08.2026 9.3
CVE-2026-57499 Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) 27.08.2026 9.1
CVE-2026-81094 mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication 29.08.2026 9.3
CVE-2026-81096 ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape 29.08.2026 9.3
CVE-2026-81098 Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport 29.08.2026 9.3
CVE-2026-81680 openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal 27.08.2026 9.3
CVE-2026-81681 openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage 27.08.2026 9.3
CVE-2026-81685 openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata 27.08.2026 9.3
CVE-2026-81694 verify-usb before 1.4.9 Output Injection via Unsanitized Filenames 28.08.2026 9.3
CVE-2026-81695 openssl_encrypt before 1.4.9 Terminal Injection via key_id 27.08.2026 9.3
CVE-2026-81696 openssl_encrypt before 1.4.9 Terminal Injection via info Command 27.08.2026 9.3
CVE-2026-81698 openssl_encrypt before 1.4.9 Shell Injection via info command 27.08.2026 9.3
CVE-2026-81700 openssl_encrypt before 1.4.9 GPG Signature Verification Bypass 27.08.2026 9.3
CVE-2026-81701 openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin 27.08.2026 9.3
CVE-2026-81702 openssl_encrypt before 1.4.9 Key Substitution via Identity Load 01.09.2026 9.3
CVE-2026-81706 openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing 27.08.2026 9.3
CVE-2026-81707 openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email 31.08.2026 9.3
CVE-2026-81714 openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass 27.08.2026 9.3
CVE-2026-81717 openssl_encrypt before 1.4.9 Integrity Bypass via Added Files 27.08.2026 9.3
CVE-2026-81719 openssl_encrypt before 1.4.9 Remote Code Execution via Plugin 27.08.2026 9.3
CVE-2026-81735 UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution 31.08.2026 10
CVE-2026-81826 Flowintel Fails to Invalidate Active Sessions After Password Change 27.08.2026 9.1
CVE-2026-74232 Zbtlink MQWrt yunmgrd Cloud C2 Implant 27.08.2026 9.3
CVE-2026-74233 Zbtlink MQWrt infosrvd Command Injection 27.08.2026 9.3
CVE-2026-81672 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81673 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81674 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81675 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-32479 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability 28.08.2026 9.3
CVE-2026-32566 WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability 27.08.2026 9.8
CVE-2026-59354 Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata 28.08.2026 9.6
CVE-2026-78260 WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability 28.08.2026 9.3
CVE-2026-78274 WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability 27.08.2026 9.1
CVE-2026-78286 WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability 28.08.2026 9.8
CVE-2026-78288 WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability 27.08.2026 9.3
CVE-2026-78292 WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability 27.08.2026 9.8
CVE-2026-59270 Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces 28.08.2026 9.4
CVE-2026-77991 Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 28.08.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-19475 CVE-2026-19475 CVE Record 02.09.2026 6.5
CVE-2026-18329 NGINX ngx_http_js_module vulnerability 02.09.2026 8.2
CVE-2026-63020 BIG-IP Configuration utility vulnerability 02.09.2026 3.1
CVE-2026-66362 NGF vulnerability 02.09.2026 8.1
CVE-2026-66842 BIG-IP and BIG-IQ Configuration utility vulnerability 02.09.2026 8.8
CVE-2026-77180 NGINX Ingress Controller vulnerability 02.09.2026 8.3
CVE-2026-78222 NGINX ngx_http_js_module vulnerability 02.09.2026 7.5
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 02.09.2026 8.1
CVE-2026-84645 02.09.2026
CVE-2026-84646 02.09.2026
CVE-2026-84647 02.09.2026
CVE-2026-84648 02.09.2026
CVE-2026-84649 02.09.2026
CVE-2026-84650 02.09.2026
CVE-2026-84651 02.09.2026
CVE-2026-84652 02.09.2026
CVE-2026-84653 02.09.2026
CVE-2026-84654 02.09.2026
CVE-2026-84655 02.09.2026
CVE-2026-84656 02.09.2026
CVE-2026-84657 02.09.2026
CVE-2026-84658 02.09.2026
CVE-2026-84659 02.09.2026
CVE-2026-84660 02.09.2026
CVE-2026-84661 02.09.2026
CVE-2026-84662 02.09.2026
CVE-2026-84663 02.09.2026
CVE-2026-84664 02.09.2026
CVE-2026-84665 02.09.2026
CVE-2026-84666 02.09.2026
CVE-2026-84667 02.09.2026
CVE-2026-84668 02.09.2026
CVE-2026-84669 02.09.2026
CVE-2026-84670 02.09.2026
CVE-2026-84671 02.09.2026
CVE-2026-84672 02.09.2026
CVE-2026-84673 02.09.2026
CVE-2026-84674 02.09.2026
CVE-2026-84675 02.09.2026
CVE-2026-84676 02.09.2026
CVE-2026-84677 02.09.2026
CVE-2026-18058 02.09.2026
CVE-2026-78408 Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority 02.09.2026
CVE-2026-78409 Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks 02.09.2026
CVE-2026-78410 Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection 02.09.2026
CVE-2026-84837 Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path 02.09.2026
CVE-2026-84838 Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() 02.09.2026
CVE-2024-7956 Sensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosaix™ Private Cloud 02.09.2026
CVE-2026-78584 Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure 02.09.2026 4.3
CVE-2026-78586 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 02.09.2026 6.5
CVE-2026-78587 Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Operations 02.09.2026 3.1
CVE-2026-78588 Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Service 02.09.2026 6.5
CVE-2026-78590 Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources 02.09.2026 7.3
CVE-2026-78591 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion 02.09.2026 6.3
CVE-2026-78594 Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service 02.09.2026 4.9
CVE-2026-78598 Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data 02.09.2026 5.4
CVE-2026-78599 Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources 02.09.2026 6.5
CVE-2026-78600 Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention 02.09.2026 3.5
CVE-2026-78601 Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure 02.09.2026 5.5
CVE-2026-78602 Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File Disclosure 02.09.2026 5.3
CVE-2026-78604 Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEM 02.09.2026 7.8
CVE-2026-78609 Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modification of Data 02.09.2026 5.4
CVE-2026-82293 Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption 02.09.2026 4.3
CVE-2026-82955 02.09.2026
CVE-2023-3360 Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection 02.09.2026 3.3
CVE-2024-3773 LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode 02.09.2026 5.9
CVE-2025-13398 02.09.2026
CVE-2025-15481 Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure 02.09.2026 5.3
CVE-2025-15485 Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call 02.09.2026 8.2
CVE-2025-15489 Passster < 4.2.24 - Password Protection Bypass 02.09.2026 5.3
CVE-2025-15490 Passster < 4.2.26 - Global Protection Bypass 02.09.2026 5.3
CVE-2025-8945 Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API 02.09.2026 5.3
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-14255 IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products 02.09.2026 5.5
CVE-2026-2811 Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection 02.09.2026 5.4
CVE-2026-79991 Authenticated SQL Injection via nested eager-loading criteria 02.09.2026
CVE-2025-15692 Icegram Express < 5.8.6 - Admin+ Stored XSS 02.09.2026 3.5
CVE-2026-10821 Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE 02.09.2026 6.6
CVE-2026-14326 Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR 02.09.2026 3.8
CVE-2026-17563 WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form 02.09.2026 5.3
CVE-2026-19698 GutenKit < 2.5.1 - Contributor+ Stored CSS Injection 02.09.2026 3.5
CVE-2026-2688 CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass 02.09.2026 6.5
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-77793 RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field 02.09.2026 5.3
CVE-2026-77794 RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity 02.09.2026 5.3
CVE-2026-78153 Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization 02.09.2026 5.3
CVE-2026-79989 Arbitrary user password reset leading to administrator account takeover 02.09.2026
CVE-2026-79990 GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete 02.09.2026
CVE-2026-81571 Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM Parameter 02.09.2026 4.8
CVE-2026-82884 All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block 02.09.2026 6.8
CVE-2026-83533 WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment 02.09.2026 5.3
CVE-2026-83547 Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets 02.09.2026 6.8
CVE-2026-8151 Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF 02.09.2026 5.4
CVE-2026-16647 Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 02.09.2026
CVE-2026-18986 Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094 02.09.2026
CVE-2026-73474 Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097 02.09.2026
CVE-2026-73475 Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095 02.09.2026
CVE-2026-73476 External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098 02.09.2026
CVE-2026-73477 Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099 02.09.2026
CVE-2026-73478 Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096 02.09.2026
CVE-2026-76755 Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 02.09.2026
CVE-2026-76756 Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 02.09.2026
CVE-2026-76757 Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 02.09.2026
CVE-2026-76758 Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 02.09.2026
CVE-2026-76782 Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 02.09.2026
CVE-2026-76759 Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 02.09.2026
CVE-2026-81158 Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113 02.09.2026
CVE-2026-81159 Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106 02.09.2026
CVE-2026-81160 Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117 02.09.2026
CVE-2026-81161 Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107 02.09.2026
CVE-2026-81162 DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112 02.09.2026
CVE-2026-81164 Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114 02.09.2026
CVE-2026-81165 Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104 02.09.2026
CVE-2026-81166 Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109 02.09.2026
CVE-2026-81167 Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103 02.09.2026
CVE-2026-81168 CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 02.09.2026
CVE-2026-81201 Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116 02.09.2026
CVE-2026-81205 LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115 02.09.2026
CVE-2026-81269 Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108 02.09.2026
CVE-2026-84217 WordPress Classified Listing plugin <= 6.1.1 - Broken Access Control vulnerability 02.09.2026 5.4
CVE-2026-66652 WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerability 02.09.2026 5.4
CVE-2026-84835 WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability 02.09.2026 5.3
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81769 WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability 02.09.2026 8.8
CVE-2026-81770 WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-81771 WordPress TrustedSite plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-81772 WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injection vulnerability 02.09.2026 8.8
CVE-2026-81774 WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability 02.09.2026 7.5
CVE-2026-81775 WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-82223 WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerability 02.09.2026 6.5
CVE-2026-83562 WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulnerability 02.09.2026 6.5
CVE-2026-84759 WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability 02.09.2026 7.1
CVE-2026-84760 WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability 02.09.2026 5.3
CVE-2026-84764 WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability 02.09.2026 8.8
CVE-2026-84770 WordPress Mang Board WP plugin <= 2.3.8 - Cross Site Request Forgery (CSRF) vulnerability 02.09.2026 8.8
CVE-2026-84771 WordPress PublishPress Permissions plugin <= 4.8.3 - Insecure Direct Object References (IDOR) vulnerability 02.09.2026 5.3
CVE-2026-84772 WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery (SSRF) vulnerability 02.09.2026 5.5
CVE-2026-84775 WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerability 02.09.2026 5.3
CVE-2026-84780 WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability 02.09.2026 5.3
CVE-2026-81283 WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability 02.09.2026 8.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-81288 WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-81289 WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.13.1 - Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-84781 WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability 02.09.2026 6.5
CVE-2026-84792 Craft CMS before 5.10.11 Broken Access Control via element-indexes 02.09.2026
CVE-2026-84793 Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name 02.09.2026
CVE-2026-84794 Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset 02.09.2026
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026
CVE-2026-84796 Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass 02.09.2026
CVE-2026-84797 Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate 02.09.2026
CVE-2026-84798 Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite 02.09.2026
CVE-2026-84799 Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations 02.09.2026
CVE-2026-84800 Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file 02.09.2026
CVE-2026-84801 Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers 02.09.2026
CVE-2026-84802 Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController 02.09.2026
CVE-2026-84803 SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist 02.09.2026
CVE-2026-84804 Kimai before 2.65.0 Authorization Bypass via Team Activity API 02.09.2026
CVE-2026-84805 Kimai 2.61.0 before 2.63.0 Authentication Bypass via API 02.09.2026
CVE-2026-84806 Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints 02.09.2026
CVE-2026-84807 Kimai before 2.65.0 Authentication Bypass via Team Creation 02.09.2026
CVE-2026-84808 Kimai before 2.65.0 Authorization Bypass via API Timesheet 02.09.2026
CVE-2026-32773 Apache Spark: XSS Vulnerability in Spark Web 3.5.4 02.09.2026
CVE-2026-19219 DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX 02.09.2026 8.1
CVE-2026-18672 RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX 02.09.2026 7.5
CVE-2026-82958 02.09.2026
CVE-2026-84175 02.09.2026
CVE-2026-53683 Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html 02.09.2026
CVE-2026-23583 02.09.2026
CVE-2026-23584 02.09.2026
CVE-2026-23585 02.09.2026
CVE-2026-23586 02.09.2026
CVE-2026-23587 02.09.2026
CVE-2026-23588 02.09.2026
CVE-2026-23589 02.09.2026
CVE-2026-23590 02.09.2026
CVE-2026-23591 02.09.2026
CVE-2025-7963 Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function 02.09.2026 6.4
CVE-2026-75528 Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log 02.09.2026 7.2
CVE-2026-14828 02.09.2026 8.8
CVE-2026-82883 WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability 02.09.2026 7.1
CVE-2026-3850 Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter 02.09.2026 6.4
CVE-2025-15663 BEAF < 4.7.19 - Author+ Stored XSS via After Label 02.09.2026
CVE-2025-15664 BEAF < 4.7.19 - Author+ Stored XSS via Before Label 02.09.2026
CVE-2026-12526 Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeover via Front-End User Update Action 02.09.2026
CVE-2026-12865 Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters 02.09.2026
CVE-2026-14215 Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger 02.09.2026
CVE-2026-15232 Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion 02.09.2026
CVE-2026-16966 Solace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content 02.09.2026
CVE-2026-16983 Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API 02.09.2026
CVE-2026-19116 WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form 02.09.2026
CVE-2026-19251 Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile Activity 02.09.2026
CVE-2026-19453 JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection 02.09.2026
CVE-2026-19704 Comments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi 02.09.2026
CVE-2026-19719 Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title 02.09.2026
CVE-2026-19723 Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler 02.09.2026
CVE-2026-74927 MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint 02.09.2026
CVE-2026-77764 GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award via Watch-Video Listeners 02.09.2026
CVE-2026-77782 Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt 02.09.2026
CVE-2026-77783 Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure 02.09.2026
CVE-2026-77784 Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as 02.09.2026
CVE-2026-77785 Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abilities API 02.09.2026
CVE-2026-77787 Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk 02.09.2026
CVE-2026-77788 Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas 02.09.2026
CVE-2026-77792 RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field 02.09.2026
CVE-2026-78151 FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response 02.09.2026
CVE-2026-79621 CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient 02.09.2026
CVE-2026-80467 Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action 02.09.2026
CVE-2026-81194 MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter 02.09.2026
CVE-2026-81195 MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route 02.09.2026
CVE-2026-81196 MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR 02.09.2026
CVE-2026-81197 MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route 02.09.2026
CVE-2026-81198 MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR 02.09.2026
CVE-2026-81199 MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route 02.09.2026
CVE-2026-81426 WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF 02.09.2026
CVE-2026-81427 WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change 02.09.2026
CVE-2026-81428 WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR 02.09.2026
CVE-2026-81432 JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF 02.09.2026
CVE-2026-81583 Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation 02.09.2026
CVE-2026-81737 FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information 02.09.2026
CVE-2026-81807 Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification 02.09.2026
CVE-2026-82182 WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation 02.09.2026
CVE-2026-82183 OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion 02.09.2026
CVE-2026-14357 DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter 02.09.2026 8.8
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8