| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-81659 | Hig | 0.39 | — | 0.00 | Aug 27, 2026 | Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export. | ||
| CVE-2026-81658 | Med | 0.42 | 6.5 | 0.00 | Aug 27, 2026 | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template… | ||
| CVE-2026-81562 | — | Med | 0.27 | 5.3 | 0.01 | Aug 27, 2026 | A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the… | |
| CVE-2026-81560 | Med | 0.34 | 5.3 | 0.01 | Aug 27, 2026 | A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed… | ||
| CVE-2026-74233 | Cri | 0.64 | 9.8 | 0.03 | Aug 27, 2026 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1… | ||
| CVE-2026-74232 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2026 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014,… | ||
| CVE-2026-66155 | Hig | 0.49 | 7.6 | 0.00 | Aug 27, 2026 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property… | ||
| CVE-2026-5218 | Med | 0.28 | 4.3 | 0.00 | Aug 27, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49. | ||
| CVE-2026-17562 | Med | 0.42 | 6.5 | 0.00 | Aug 27, 2026 | Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0. | ||
| CVE-2026-81625 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2026 | A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system. | ||
| CVE-2026-81581 | Hig | 0.57 | 8.8 | 0.00 | Aug 27, 2026 | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits… | ||
| CVE-2026-81579 | Hig | 0.57 | 8.8 | 0.00 | Aug 27, 2026 | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code,… | ||
| CVE-2026-81576 | Hig | 0.50 | 7.7 | 0.00 | Aug 27, 2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information… | ||
| CVE-2026-81575 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that… | ||
| CVE-2026-81574 | Hig | 0.53 | 8.2 | 0.00 | Aug 27, 2026 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory… | ||
| CVE-2026-81573 | Hig | 0.56 | 8.6 | 0.00 | Aug 27, 2026 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can… | ||
| CVE-2026-81572 | Hig | 0.51 | 7.8 | 0.00 | Aug 27, 2026 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or… | ||
| CVE-2026-81279 | Med | 0.35 | 5.4 | 0.00 | Aug 27, 2026 | Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions. | ||
| CVE-2026-81277 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | ||
| CVE-2026-81276 | Med | 0.34 | 5.3 | 0.00 | Aug 27, 2026 | Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | ||
| CVE-2026-81274 | Med | 0.34 | 5.3 | 0.00 | Aug 27, 2026 | Subscriber Broken Access Control in Ditty <= 3.1.67 versions. | ||
| CVE-2026-81273 | Hig | 0.53 | 8.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. | ||
| CVE-2026-81272 | Med | 0.32 | 4.9 | 0.00 | Aug 27, 2026 | Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions. | ||
| CVE-2026-81271 | Hig | 0.50 | 8.8 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | ||
| CVE-2026-80433 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | ||
| CVE-2026-78293 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | ||
| CVE-2026-78292 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2026 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | ||
| CVE-2026-78289 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | ||
| CVE-2026-78288 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | ||
| CVE-2026-78286 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2026 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | ||
| CVE-2026-78285 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | ||
| CVE-2026-78283 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | ||
| CVE-2026-78281 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | ||
| CVE-2026-78276 | Hig | 0.47 | 7.2 | 0.01 | Aug 27, 2026 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78275 | Med | 0.44 | 6.8 | 0.01 | Aug 27, 2026 | Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78274 | Cri | 0.59 | 9.1 | 0.01 | Aug 27, 2026 | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78273 | Med | 0.42 | 6.5 | 0.00 | Aug 27, 2026 | Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions. | ||
| CVE-2026-78271 | Hig | 0.47 | 7.2 | 0.00 | Aug 27, 2026 | Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | ||
| CVE-2026-78261 | Hig | 0.46 | 7.1 | 0.00 | Aug 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | ||
| CVE-2026-78260 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | ||
| CVE-2026-78257 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2026 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | ||
| CVE-2026-75020 | Hig | 0.53 | 8.1 | 0.01 | Aug 27, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the… | ||
| CVE-2026-75005 | Hig | 0.42 | 7.5 | 0.01 | Aug 27, 2026 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version… | ||
| CVE-2026-74848 | Hig | 0.49 | 7.5 | 0.01 | Aug 27, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0… | ||
| CVE-2026-59355 | Med | 0.40 | 6.1 | 0.00 | Aug 27, 2026 | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result… | ||
| CVE-2026-59354 | Cri | 0.55 | 9.6 | 0.00 | Aug 27, 2026 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An… | ||
| CVE-2026-32566 | Cri | 0.64 | 9.8 | 0.00 | Aug 27, 2026 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-32564 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-32550 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | ||
| CVE-2026-32479 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. |
- risk 0.39cvss —epss 0.00
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
- risk 0.42cvss 6.5epss 0.00
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template…
- risk 0.27cvss 5.3epss 0.01
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the…
- risk 0.34cvss 5.3epss 0.01
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed…
- risk 0.64cvss 9.8epss 0.03
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1…
- risk 0.64cvss 9.8epss 0.01
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014,…
- risk 0.49cvss 7.6epss 0.00
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property…
- risk 0.28cvss 4.3epss 0.00
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49.
- risk 0.42cvss 6.5epss 0.00
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0.
- risk 0.57cvss 8.8epss 0.01
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
- risk 0.57cvss 8.8epss 0.00
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits…
- risk 0.57cvss 8.8epss 0.00
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code,…
- risk 0.50cvss 7.7epss 0.00
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information…
- risk 0.49cvss 7.5epss 0.00
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that…
- risk 0.53cvss 8.2epss 0.00
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory…
- risk 0.56cvss 8.6epss 0.00
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can…
- risk 0.51cvss 7.8epss 0.00
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or…
- risk 0.35cvss 5.4epss 0.00
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
- risk 0.55cvss 8.5epss 0.00
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
- risk 0.34cvss 5.3epss 0.00
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
- risk 0.32cvss 4.9epss 0.00
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
- risk 0.50cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
- risk 0.47cvss 7.2epss 0.01
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.44cvss 6.8epss 0.01
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.59cvss 9.1epss 0.01
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
- risk 0.47cvss 7.2epss 0.00
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
- risk 0.57cvss 8.8epss 0.01
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
- risk 0.53cvss 8.1epss 0.01
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the…
- risk 0.42cvss 7.5epss 0.01
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version…
- risk 0.49cvss 7.5epss 0.01
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0…
- risk 0.40cvss 6.1epss 0.00
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result…
- risk 0.55cvss 9.6epss 0.00
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.