| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-85242 | Med | 0.38 | — | 0.00 | Sep 3, 2026 | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network… | ||
| CVE-2026-85186 | Med | 0.41 | 6.3 | 0.00 | Sep 3, 2026 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument… | ||
| CVE-2026-84849 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | ||
| CVE-2026-84848 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | ||
| CVE-2026-84847 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | ||
| CVE-2026-84836 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | ||
| CVE-2026-84834 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | ||
| CVE-2026-84814 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | ||
| CVE-2026-84813 | Cri | 0.53 | 9.3 | 0.00 | Sep 3, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | ||
| CVE-2026-84812 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||
| CVE-2026-84779 | Hig | 0.53 | 8.1 | 0.00 | Sep 3, 2026 | Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. | ||
| CVE-2026-84778 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | ||
| CVE-2026-84777 | Hig | 0.41 | 7.4 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | ||
| CVE-2026-84776 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | ||
| CVE-2026-84774 | Med | 0.33 | 6.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. | ||
| CVE-2026-84773 | Hig | 0.47 | 7.2 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | ||
| CVE-2026-84769 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||
| CVE-2026-84768 | Cri | 0.60 | 9.3 | 0.00 | Sep 3, 2026 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | ||
| CVE-2026-84767 | Med | 0.34 | 5.3 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||
| CVE-2026-84766 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||
| CVE-2026-84765 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | ||
| CVE-2026-84763 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions. | ||
| CVE-2026-84762 | Med | 0.34 | 5.3 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | ||
| CVE-2026-84761 | Hig | 0.47 | 7.2 | 0.00 | Sep 3, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | ||
| CVE-2026-84758 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||
| CVE-2026-84757 | Hig | 0.53 | 8.2 | 0.00 | Sep 3, 2026 | Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. | ||
| CVE-2026-84756 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | ||
| CVE-2026-84755 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | ||
| CVE-2026-84754 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||
| CVE-2026-84753 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||
| CVE-2026-84752 | Hig | 0.57 | 8.8 | 0.00 | Sep 3, 2026 | Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | ||
| CVE-2026-84736 | Hig | 0.47 | — | 0.00 | Sep 3, 2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or… | ||
| CVE-2026-84238 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | ||
| CVE-2026-84215 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | ||
| CVE-2026-81776 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | ||
| CVE-2026-81773 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||
| CVE-2026-81300 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | ||
| CVE-2026-81295 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | ||
| CVE-2026-81292 | Hig | 0.46 | 7.1 | 0.00 | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | ||
| CVE-2026-81282 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | ||
| CVE-2026-81281 | Med | 0.42 | 6.5 | 0.00 | Sep 3, 2026 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | ||
| CVE-2026-75602 | Med | 0.35 | 6.5 | 0.00 | Sep 3, 2026 | OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before… | ||
| CVE-2026-85239 | Med | 0.35 | 6.5 | 0.00 | Sep 3, 2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the… | ||
| CVE-2026-85238 | Med | 0.37 | 6.8 | 0.00 | Sep 3, 2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session… | ||
| CVE-2026-85237 | Hig | 0.46 | 8.1 | 0.00 | Sep 3, 2026 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker… | ||
| CVE-2026-85236 | Hig | 0.50 | 8.8 | 0.00 | Sep 3, 2026 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an… | ||
| CVE-2026-85138 | Hig | 0.47 | 7.3 | 0.00 | Sep 3, 2026 | A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public… | ||
| CVE-2026-85137 | Hig | 0.47 | 7.3 | 0.00 | Sep 3, 2026 | A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit… | ||
| CVE-2026-84967 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2026 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades… | ||
| CVE-2026-84966 | Med | 0.33 | 5.1 | 0.00 | Sep 3, 2026 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory… |
- risk 0.38cvss —epss 0.00
PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network…
- risk 0.41cvss 6.3epss 0.00
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument…
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
- risk 0.64cvss 9.8epss 0.00
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- risk 0.53cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
- risk 0.53cvss 8.1epss 0.00
Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.
- risk 0.41cvss 7.4epss 0.00
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
- risk 0.33cvss 6.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
- risk 0.47cvss 7.2epss 0.00
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
- risk 0.38cvss 5.9epss 0.00
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
- risk 0.47cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
- risk 0.53cvss 8.2epss 0.00
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- risk 0.57cvss 8.8epss 0.00
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
- risk 0.47cvss —epss 0.00
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
- risk 0.35cvss 6.5epss 0.00
OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before…
- risk 0.35cvss 6.5epss 0.00
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…
- risk 0.37cvss 6.8epss 0.00
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…
- risk 0.46cvss 8.1epss 0.00
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker…
- risk 0.50cvss 8.8epss 0.00
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…
- risk 0.28cvss 4.3epss 0.00
A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades…
- risk 0.33cvss 5.1epss 0.00
An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory…