| CVE-2026-84800 | HIGH | 7.1 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsControlle… | 2026-09-02 |
| CVE-2026-84801 | HIGH | 8.8 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, all… | 2026-09-02 |
| CVE-2026-84802 | MEDIUM | 4.3 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsControll… | 2026-09-02 |
| CVE-2026-84803 | CRITICAL | 9.0 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplet… | 2026-09-02 |
| CVE-2026-84804 | MEDIUM | 5.4 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, … | 2026-09-02 |
| CVE-2026-84805 | MEDIUM | 4.3 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privileg… | 2026-09-02 |
| CVE-2026-84806 | MEDIUM | 5.4 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows auth… | 2026-09-02 |
| CVE-2026-84807 | MEDIUM | 5.4 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the def… | 2026-09-02 |
| CVE-2026-84808 | MEDIUM | 4.3 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collectio… | 2026-09-02 |
| CVE-2026-84835 | MEDIUM | 5.3 | Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Con… | 2026-09-02 |
| CVE-2026-16647 | NA | N/A | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Fun… | 2026-09-02 |
| CVE-2026-18986 | MEDIUM | 4.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal E… | 2026-09-02 |
| CVE-2026-73474 | NA | N/A | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forg… | 2026-09-02 |
| CVE-2026-73475 | NA | N/A | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects C… | 2026-09-02 |
| CVE-2026-73476 | NA | N/A | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalat… | 2026-09-02 |
| CVE-2026-73477 | NA | N/A | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick … | 2026-09-02 |
| CVE-2026-73478 | NA | N/A | Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff version… | 2026-09-02 |
| CVE-2026-76755 | NA | N/A | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.… | 2026-09-02 |
| CVE-2026-76756 | NA | N/A | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.… | 2026-09-02 |
| CVE-2026-76757 | NA | N/A | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.… | 2026-09-02 |
| CVE-2026-76758 | NA | N/A | Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.… | 2026-09-02 |
| CVE-2026-76759 | NA | N/A | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.… | 2026-09-02 |
| CVE-2026-76782 | NA | N/A | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.… | 2026-09-02 |
| CVE-2026-81158 | NA | N/A | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity… | 2026-09-02 |
| CVE-2026-81159 | NA | N/A | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affe… | 2026-09-02 |
| CVE-2026-81160 | NA | N/A | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal S… | 2026-09-02 |
| CVE-2026-81161 | NA | N/A | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privileg… | 2026-09-02 |
| CVE-2026-81162 | NA | N/A | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) … | 2026-09-02 |
| CVE-2026-81164 | NA | N/A | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity P… | 2026-09-02 |
| CVE-2026-81165 | NA | N/A | Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versi… | 2026-09-02 |
| CVE-2026-81166 | NA | N/A | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue a… | 2026-09-02 |
| CVE-2026-81167 | MEDIUM | 4.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A… | 2026-09-02 |
| CVE-2026-81168 | NA | N/A | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows… | 2026-09-02 |
| CVE-2026-81201 | NA | N/A | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal M… | 2026-09-02 |
| CVE-2026-81205 | NA | N/A | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal L… | 2026-09-02 |
| CVE-2026-81269 | NA | N/A | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data fie… | 2026-09-02 |
| CVE-2023-3360 | LOW | 3.3 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could … | 2026-09-02 |
| CVE-2024-3773 | MEDIUM | 5.9 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode at… | 2026-09-02 |
| CVE-2024-7956 | NA | N/A | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. … | 2026-09-02 |
| CVE-2025-13398 | NA | N/A | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned … | 2026-09-02 |
| CVE-2025-15481 | MEDIUM | 5.3 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that disc… | 2026-09-02 |
| CVE-2025-15485 | HIGH | 8.2 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoint… | 2026-09-02 |
| CVE-2025-15489 | MEDIUM | 5.3 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthe… | 2026-09-02 |
| CVE-2025-15490 | MEDIUM | 5.3 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticat… | 2026-09-02 |
| CVE-2025-15692 | LOW | 3.5 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before o… | 2026-09-02 |
| CVE-2025-8945 | MEDIUM | 5.3 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protecti… | 2026-09-02 |
| CVE-2025-9314 | CRITICAL | 9.8 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi… | 2026-09-02 |
| CVE-2026-10821 | MEDIUM | 6.6 | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origin… | 2026-09-02 |
| CVE-2026-14255 | MEDIUM | 5.5 | A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Rec… | 2026-09-02 |
| CVE-2026-14326 | LOW | 3.8 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments … | 2026-09-02 |