CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 12.09.2026 9.8
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 12.09.2026 9.8
CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 12.09.2026 10
CVE-2026-87719 Deserialization of Untrusted Data in GitLab 12.09.2026 9.9
CVE-2026-90456 11.09.2026 9.2
CVE-2026-53952 GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw 11.09.2026 9.8
CVE-2026-54072 Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL 11.09.2026 9.3
CVE-2026-62103 WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-62105 WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-82617 Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns 11.09.2026 10
CVE-2026-72709 SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur 11.09.2026 9.3
CVE-2026-72710 SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection 11.09.2026 9.3
CVE-2026-54047 Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation 11.09.2026 9.2
CVE-2026-3869 11.09.2026 9.2
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026 9.3
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 9.4
CVE-2026-87987 11.09.2026 10
CVE-2026-87988 11.09.2026 10
CVE-2026-87983 11.09.2026 9.2
CVE-2026-87984 11.09.2026 9.3
CVE-2026-87985 11.09.2026 10
CVE-2026-87986 11.09.2026 10
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026 9.2
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026 9.2
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026 9.3
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026 9.3
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026 9.3
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026 9.3
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026 9.3
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026 9.3
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026 9.3
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026 9.2
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 11.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 11.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 11.09.2026 9.1
CVE-2026-75940 11.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-89094 10.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 11.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 11.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 11.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 11.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 11.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 10.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 10.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 10.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 10.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 11.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 11.09.2026 9.2
CVE-2026-21096 11.09.2026 9.2
CVE-2026-21102 11.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 10.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 12.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 11.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 11.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 11.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 11.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 11.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 11.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 11.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 11.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 10.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 10.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 10.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 10.09.2026 9.1
CVE-2026-62647 08.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 11.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 11.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10
CVE-2026-86478 09.09.2026 9.8
CVE-2026-86480 09.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 09.09.2026 9.8
CVE-2026-80238 08.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 08.09.2026 9.2
CVE-2026-61410 09.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 08.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 08.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 11.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 09.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 08.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 08.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 11.09.2026 9.4
CVE-2026-16876 08.09.2026 9.3
CVE-2026-86259 OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation 11.09.2026 9
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 08.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-10148 Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter 12.09.2026 6.4
CVE-2026-15451 MemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation 12.09.2026 8.8
CVE-2026-90533 Flowise before 3.1.4 Broken Access Control via organizationuser 12.09.2026
CVE-2026-90534 Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method 12.09.2026
CVE-2026-90535 Flowise before 3.1.4 Denial of Service via text-to-speech/abort 12.09.2026
CVE-2026-90536 WWBN AVideo Missing Authorization via adsInfo API Endpoint 12.09.2026
CVE-2026-90537 WWBN AVideo Scheduler sendEmail Missing Authorization via Token 12.09.2026
CVE-2026-90538 WWBN AVideo Missing Authorization via playlistsFromUser.json.php 12.09.2026
CVE-2026-90539 WWBN AVideo Missing Authentication via menuItems.json.php 12.09.2026
CVE-2026-90540 WWBN AVideo Missing Authorization via playListAddVideo.json.php 12.09.2026
CVE-2026-90541 WWBN AVideo Unauthenticated Information Disclosure via menus.json.php 12.09.2026
CVE-2026-90542 WWBN AVideo Missing Authorization via remindMe.json.php 12.09.2026
CVE-2026-90543 WWBN AVideo Missing Authentication via socketMessageLiveOwner.json.php 12.09.2026
CVE-2026-90544 WWBN AVideo Missing Authorization via videoAddViewCount.json.php 12.09.2026
CVE-2026-90545 WWBN AVideo Missing Authorization via commentAddNew.json.php 12.09.2026
CVE-2026-90546 WWBN AVideo Missing Authorization via like.json.php 12.09.2026
CVE-2026-90547 WWBN AVideo Missing Authorization via getBookmarks.json.php 12.09.2026
CVE-2026-90548 WWBN AVideo Missing Authorization in ImageGallery list.json.php 12.09.2026
CVE-2026-90549 WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint 12.09.2026
CVE-2026-90550 WWBN AVideo Missing Authorization via mediaSession.json.php 12.09.2026
CVE-2026-90551 WWBN AVideo Missing Authorization via video_from_program API 12.09.2026
CVE-2026-90552 WWBN AVideo Missing Authorization via Playlists_schedules list.json.php 12.09.2026
CVE-2026-90553 vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor 12.09.2026
CVE-2026-90554 vLLM before 0.28.0 Denial of Service via audio extraction 12.09.2026
CVE-2026-90555 vLLM before 0.28.0 Denial of Service via Audio Header 12.09.2026
CVE-2026-90472 msgpack-java through 0.9.12 Stack Overflow via Nested Arrays 12.09.2026
CVE-2026-90473 msgpack-java through 0.9.12 Integer Overflow via MAP32 12.09.2026
CVE-2026-90474 MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass 12.09.2026
CVE-2026-89172 Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms 12.09.2026
CVE-2026-11355 DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions 12.09.2026 5.3
CVE-2026-16482 rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter 12.09.2026 7.5
CVE-2026-17585 Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter 12.09.2026 5.3
CVE-2026-77161 Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Injection via Parameter Name 12.09.2026 6.5
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 12.09.2026 9.8
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 12.09.2026 9.8
CVE-2026-78175 Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution 12.09.2026 8.8
CVE-2026-85198 MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path 12.09.2026 6.5
CVE-2026-85200 GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion 12.09.2026 7.5
CVE-2026-75800 Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse 12.09.2026
CVE-2026-77005 Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal 12.09.2026
CVE-2026-77006 WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal 12.09.2026
CVE-2026-77689 Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass 12.09.2026
CVE-2026-77705 Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover 12.09.2026
CVE-2026-77752 Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation 12.09.2026
CVE-2026-77753 Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords 12.09.2026
CVE-2026-78152 SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema 12.09.2026
CVE-2026-80491 SAMO Forms <= 1.0.0 - Unauthenticated SQLi 12.09.2026
CVE-2026-80494 Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download 12.09.2026
CVE-2026-81090 Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF 12.09.2026
CVE-2026-81402 DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload 12.09.2026
CVE-2026-81429 Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF 12.09.2026
CVE-2026-81742 BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation 12.09.2026
CVE-2026-82845 Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection 12.09.2026
CVE-2026-82847 Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights 12.09.2026
CVE-2026-82851 Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR 12.09.2026
CVE-2026-83532 Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes 12.09.2026
CVE-2026-84023 BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF 12.09.2026
CVE-2026-84024 BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF 12.09.2026
CVE-2026-84025 BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR 12.09.2026
CVE-2026-84047 Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action 12.09.2026
CVE-2026-84099 IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php 12.09.2026
CVE-2026-84171 WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload 12.09.2026
CVE-2026-85681 WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update 12.09.2026
CVE-2026-86790 WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode 12.09.2026
CVE-2026-87759 Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation 12.09.2026
CVE-2026-87797 Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note 12.09.2026
CVE-2026-87842 Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure 12.09.2026
CVE-2026-87888 YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route 12.09.2026
CVE-2026-87891 Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API 12.09.2026
CVE-2026-87892 Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass 12.09.2026
CVE-2026-87894 Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR 12.09.2026
CVE-2026-87916 WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure 12.09.2026
CVE-2026-87918 WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions 12.09.2026
CVE-2026-87919 Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletion via Shortcode 12.09.2026