| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73312 | Hig | 0.48 | 7.4 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token… | ||
| CVE-2026-73311 | Hig | 0.48 | 7.4 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed… | ||
| CVE-2026-73310 | Med | 0.38 | 5.9 | 0.00 | Sep 8, 2026 | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can… | ||
| CVE-2026-73309 | Hig | 0.48 | 7.4 | 0.01 | Sep 8, 2026 | XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy… | ||
| CVE-2026-33920 | — | Low | 0.23 | 3.5 | 0.00 | Sep 8, 2026 | A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials.… | |
| CVE-2026-33391 | Med | 0.35 | 5.4 | 0.00 | Sep 8, 2026 | An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and… | ||
| CVE-2026-33389 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle… | ||
| CVE-2026-33388 | Hig | 0.48 | 7.4 | 0.00 | Sep 8, 2026 | An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The… | ||
| CVE-2026-33387 | Med | 0.30 | 4.6 | 0.00 | Sep 8, 2026 | A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered… | ||
| CVE-2026-79603 | Med | 0.21 | 4.3 | 0.00 | Sep 8, 2026 | x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can… | ||
| CVE-2026-79602 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2026 | A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. | ||
| CVE-2026-77106 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | ||
| CVE-2026-77105 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2026 | CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server. | ||
| CVE-2026-77104 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77103 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77102 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77101 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | ||
| CVE-2026-77098 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | ||
| CVE-2026-77097 | Hig | 0.53 | 8.2 | 0.00 | Sep 8, 2026 | Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | ||
| CVE-2026-77092 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. | ||
| CVE-2026-77091 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store. | ||
| CVE-2026-77089 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | ||
| CVE-2026-75021 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the… | ||
| CVE-2026-62437 | Med | 0.35 | 6.5 | 0.00 | Sep 8, 2026 | When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that… | ||
| CVE-2026-19203 | Hig | 0.54 | — | 0.00 | Sep 8, 2026 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a… | ||
| CVE-2026-12611 | Hig | 0.57 | — | 0.00 | Sep 8, 2026 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race condition in the server when handling RST_STREAM… | ||
| CVE-2026-11573 | Hig | 0.46 | — | 0.00 | Sep 8, 2026 | Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no… | ||
| CVE-2026-86714 | Med | 0.28 | 5.4 | 0.00 | Sep 8, 2026 | PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack… | ||
| CVE-2026-86713 | Hig | 0.39 | 7.1 | 0.00 | Sep 8, 2026 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by… | ||
| CVE-2026-86712 | Hig | 0.50 | 8.8 | 0.01 | Sep 8, 2026 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into… | ||
| CVE-2026-86711 | Hig | 0.41 | 7.4 | 0.00 | Sep 8, 2026 | electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system… | ||
| CVE-2026-80219 | 0.00 | — | 0.00 | Sep 8, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | |||
| CVE-2026-78234 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.… | ||
| CVE-2026-77968 | Hig | 0.53 | 8.2 | 0.00 | Sep 8, 2026 | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access… | ||
| CVE-2026-76931 | Med | 0.35 | 6.4 | 0.00 | Sep 8, 2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | ||
| CVE-2026-74860 | Hig | 0.55 | 8.5 | 0.01 | Sep 8, 2026 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX… | ||
| CVE-2026-3174 | Hig | 0.42 | 7.5 | 0.00 | Sep 8, 2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to… | ||
| CVE-2026-2520 | Med | 0.28 | 5.4 | 0.00 | Sep 8, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for… | ||
| CVE-2026-18021 | Med | 0.35 | 6.5 | 0.00 | Sep 8, 2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly… | ||
| CVE-2026-17509 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | ||
| CVE-2026-16502 | Hig | 0.50 | 8.8 | 0.00 | Sep 8, 2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access… | ||
| CVE-2026-12230 | Med | 0.42 | 6.4 | 0.00 | Sep 8, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output… | ||
| CVE-2026-77654 | Med | 0.40 | — | 0.00 | Sep 8, 2026 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the… | ||
| CVE-2026-19614 | Med | 0.34 | — | 0.00 | Sep 8, 2026 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | ||
| CVE-2026-9331 | Hig | 0.46 | 7.1 | 0.00 | Sep 8, 2026 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This… | ||
| CVE-2026-86590 | Med | 0.34 | — | 0.00 | Sep 8, 2026 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery… | ||
| CVE-2026-85400 | Hig | 0.42 | — | 0.00 | Sep 8, 2026 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a… | ||
| CVE-2026-77132 | Med | 0.27 | — | 0.00 | Sep 8, 2026 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted… | ||
| CVE-2026-86597 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in… | ||
| CVE-2026-86550 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the… |
- risk 0.48cvss 7.4epss 0.00
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token…
- risk 0.48cvss 7.4epss 0.01
XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed…
- risk 0.38cvss 5.9epss 0.00
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can…
- risk 0.48cvss 7.4epss 0.01
XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy…
- risk 0.23cvss 3.5epss 0.00
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials.…
- risk 0.35cvss 5.4epss 0.00
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and…
- risk 0.49cvss 7.5epss 0.00
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle…
- risk 0.48cvss 7.4epss 0.00
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The…
- risk 0.30cvss 4.6epss 0.00
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered…
- risk 0.21cvss 4.3epss 0.00
x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can…
- risk 0.57cvss 8.8epss 0.00
A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
- risk 0.57cvss 8.8epss 0.01
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
- risk 0.57cvss 8.8epss 0.00
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
- risk 0.49cvss 7.5epss 0.01
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.01
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.00
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.49cvss 7.5epss 0.00
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- risk 0.64cvss 9.8epss 0.00
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- risk 0.53cvss 8.2epss 0.00
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- risk 0.64cvss 9.8epss 0.00
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
- risk 0.51cvss 7.8epss 0.00
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
- risk 0.64cvss 9.8epss 0.01
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
- risk 0.53cvss 8.1epss 0.01
fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the…
- risk 0.35cvss 6.5epss 0.00
When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that…
- risk 0.54cvss —epss 0.00
A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a…
- risk 0.57cvss —epss 0.00
A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race condition in the server when handling RST_STREAM…
- risk 0.46cvss —epss 0.00
Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no…
- risk 0.28cvss 5.4epss 0.00
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack…
- risk 0.39cvss 7.1epss 0.00
PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by…
- risk 0.50cvss 8.8epss 0.01
SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into…
- risk 0.41cvss 7.4epss 0.00
electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system…
- CVE-2026-80219Sep 8, 2026risk 0.00cvss —epss 0.00
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
- risk 0.64cvss 9.9epss 0.00
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.…
- risk 0.53cvss 8.2epss 0.00
A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access…
- risk 0.35cvss 6.4epss 0.00
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
- risk 0.55cvss 8.5epss 0.01
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX…
- risk 0.42cvss 7.5epss 0.00
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to…
- risk 0.28cvss 5.4epss 0.00
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for…
- risk 0.35cvss 6.5epss 0.00
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly…
- risk 0.42cvss 6.5epss 0.00
The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
- risk 0.50cvss 8.8epss 0.00
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access…
- risk 0.42cvss 6.4epss 0.00
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output…
- risk 0.40cvss —epss 0.00
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the…
- risk 0.34cvss —epss 0.00
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
- risk 0.46cvss 7.1epss 0.00
The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This…
- risk 0.34cvss —epss 0.00
In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery…
- risk 0.42cvss —epss 0.00
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a…
- risk 0.27cvss —epss 0.00
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted…
- risk 0.42cvss 6.5epss 0.00
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in…
- risk 0.42cvss 6.5epss 0.00
NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the…