| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-80934 | 0.00 | — | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are… | |||
| CVE-2026-80933 | Hig | 0.44 | 7.8 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the… | ||
| CVE-2026-80932 | Hig | 0.48 | 8.4 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for… | ||
| CVE-2026-80931 | Hig | 0.44 | 7.8 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device.… | ||
| CVE-2026-80930 | 0.00 | — | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before… | |||
| CVE-2026-80929 | Hig | 0.44 | 7.8 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user… | ||
| CVE-2026-80928 | Hig | 0.44 | 7.8 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a… | ||
| CVE-2026-80927 | 0.00 | — | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized… | |||
| CVE-2026-80926 | Cri | 0.57 | 9.8 | 0.00 | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning… | ||
| CVE-2026-79035 | 0.00 | — | 0.00 | Sep 11, 2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |||
| CVE-2026-78547 | Med | 0.29 | — | 0.00 | Sep 11, 2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | ||
| CVE-2026-78546 | Med | 0.31 | — | 0.00 | Sep 11, 2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | ||
| CVE-2026-77490 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-68526 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource… | ||
| CVE-2026-54135 | Hig | 0.42 | 7.5 | 0.01 | Sep 11, 2026 | AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory… | ||
| CVE-2026-53952 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The… | ||
| CVE-2026-52630 | 0.00 | — | 0.00 | Sep 11, 2026 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php | |||
| CVE-2026-49463 | Med | 0.35 | 6.5 | 0.00 | Sep 11, 2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from… | ||
| CVE-2026-49462 | Med | 0.27 | 5.3 | 0.00 | Sep 11, 2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL… | ||
| CVE-2026-89329 | Med | 0.40 | 6.2 | 0.00 | Sep 11, 2026 | A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial… | ||
| CVE-2026-81910 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as… | ||
| CVE-2026-79396 | 0.00 | — | 0.00 | Sep 11, 2026 | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full… | |||
| CVE-2026-79395 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2026 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged… | ||
| CVE-2026-79394 | 0.00 | — | 0.00 | Sep 11, 2026 | An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video… | |||
| CVE-2026-79393 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2026 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially… | ||
| CVE-2026-79362 | 0.00 | — | 0.00 | Sep 11, 2026 | Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate… | |||
| CVE-2026-71646 | 0.00 | — | 0.00 | Sep 11, 2026 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp | |||
| CVE-2026-62140 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | ||
| CVE-2026-62139 | Med | 0.28 | 4.3 | 0.00 | Sep 11, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | ||
| CVE-2026-62138 | Med | 0.42 | 6.5 | 0.00 | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | ||
| CVE-2026-62137 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | ||
| CVE-2026-62136 | Med | 0.27 | 5.3 | 0.00 | Sep 11, 2026 | Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | ||
| CVE-2026-62135 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. | ||
| CVE-2026-62134 | Med | 0.28 | 4.3 | 0.00 | Sep 11, 2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | ||
| CVE-2026-62133 | Med | 0.35 | 5.4 | 0.00 | Sep 11, 2026 | Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. | ||
| CVE-2026-62132 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | ||
| CVE-2026-62114 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | ||
| CVE-2026-62113 | Med | 0.21 | 4.3 | 0.00 | Sep 11, 2026 | Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | ||
| CVE-2026-62112 | Hig | 0.49 | 7.6 | 0.00 | Sep 11, 2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. | ||
| CVE-2026-62111 | Med | 0.42 | 6.5 | 0.00 | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | ||
| CVE-2026-62110 | Med | 0.42 | 6.5 | 0.00 | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | ||
| CVE-2026-62109 | Hig | 0.49 | 7.6 | 0.00 | Sep 11, 2026 | Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | ||
| CVE-2026-62107 | Hig | 0.57 | 8.8 | 0.00 | Sep 11, 2026 | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | ||
| CVE-2026-62106 | Hig | 0.57 | 8.8 | 0.00 | Sep 11, 2026 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | ||
| CVE-2026-62105 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. | ||
| CVE-2026-62103 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2026 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | ||
| CVE-2026-62102 | Hig | 0.57 | 8.8 | 0.00 | Sep 11, 2026 | Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | ||
| CVE-2026-62089 | Hig | 0.46 | 7.1 | 0.00 | Sep 11, 2026 | Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | ||
| CVE-2026-62088 | Med | 0.27 | 5.3 | 0.00 | Sep 11, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4. | ||
| CVE-2026-54072 | Cri | 0.53 | 9.3 | 0.00 | Sep 11, 2026 | Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server… |
- CVE-2026-80934Sep 11, 2026risk 0.00cvss —epss 0.00
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the…
- risk 0.48cvss 8.4epss 0.00
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device.…
- CVE-2026-80930Sep 11, 2026risk 0.00cvss —epss 0.00
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user…
- risk 0.44cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a…
- CVE-2026-80927Sep 11, 2026risk 0.00cvss —epss 0.00
In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized…
- risk 0.57cvss 9.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning…
- CVE-2026-79035Sep 11, 2026risk 0.00cvss —epss 0.00
A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.
- risk 0.29cvss —epss 0.00
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
- risk 0.31cvss —epss 0.00
Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
- risk 0.40cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.27cvss —epss 0.00
Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource…
- risk 0.42cvss 7.5epss 0.01
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory…
- risk 0.64cvss 9.8epss 0.00
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The…
- CVE-2026-52630Sep 11, 2026risk 0.00cvss —epss 0.00
SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
- risk 0.35cvss 6.5epss 0.00
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from…
- risk 0.27cvss 5.3epss 0.00
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL…
- risk 0.40cvss 6.2epss 0.00
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial…
- risk 0.38cvss —epss 0.00
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as…
- CVE-2026-79396Sep 11, 2026risk 0.00cvss —epss 0.00
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full…
- risk 0.64cvss 9.8epss 0.00
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged…
- CVE-2026-79394Sep 11, 2026risk 0.00cvss —epss 0.00
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video…
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially…
- CVE-2026-79362Sep 11, 2026risk 0.00cvss —epss 0.00
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate…
- CVE-2026-71646Sep 11, 2026risk 0.00cvss —epss 0.00
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
- risk 0.28cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
- risk 0.27cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.
- risk 0.35cvss 5.4epss 0.00
Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.
- risk 0.34cvss 5.3epss 0.00
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
- risk 0.21cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.
- risk 0.49cvss 7.6epss 0.00
Editor SQL Injection in Amelia <= 2.4.9 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
- risk 0.49cvss 7.6epss 0.00
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
- risk 0.57cvss 8.8epss 0.00
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
- risk 0.46cvss 7.1epss 0.00
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
- risk 0.27cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.
- risk 0.53cvss 9.3epss 0.00
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server…