| CVE-2026-17563 | MEDIUM | 5.3 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when p… | 2026-09-02 |
| CVE-2026-19698 | LOW | 3.5 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post bef… | 2026-09-02 |
| CVE-2026-2688 | MEDIUM | 6.5 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded param… | 2026-09-02 |
| CVE-2026-2811 | MEDIUM | 5.4 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient in… | 2026-09-02 |
| CVE-2026-4357 | CRITICAL | 10.0 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug… | 2026-09-02 |
| CVE-2026-77009 | CRITICAL | 9.9 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe… | 2026-09-02 |
| CVE-2026-77793 | MEDIUM | 5.3 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration… | 2026-09-02 |
| CVE-2026-77794 | MEDIUM | 5.3 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier … | 2026-09-02 |
| CVE-2026-78153 | MEDIUM | 5.3 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking i… | 2026-09-02 |
| CVE-2026-78584 | MEDIUM | 4.3 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via… | 2026-09-02 |
| CVE-2026-78586 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E… | 2026-09-02 |
| CVE-2026-78587 | LOW | 3.1 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations v… | 2026-09-02 |
| CVE-2026-78588 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via… | 2026-09-02 |
| CVE-2026-78590 | HIGH | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe… | 2026-09-02 |
| CVE-2026-78591 | MEDIUM | 6.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe… | 2026-09-02 |
| CVE-2026-78594 | MEDIUM | 4.9 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service… | 2026-09-02 |
| CVE-2026-78598 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure vi… | 2026-09-02 |
| CVE-2026-78599 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe… | 2026-09-02 |
| CVE-2026-78600 | LOW | 3.5 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privileg… | 2026-09-02 |
| CVE-2026-78601 | MEDIUM | 5.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). … | 2026-09-02 |
| CVE-2026-78602 | MEDIUM | 5.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server… | 2026-09-02 |
| CVE-2026-78604 | HIGH | 7.8 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege e… | 2026-09-02 |
| CVE-2026-78609 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification o… | 2026-09-02 |
| CVE-2026-79989 | NA | N/A | The vulnerability allows any authenticated user to change their own password without providing the current pas… | 2026-09-02 |
| CVE-2026-79990 | NA | N/A | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout … | 2026-09-02 |
| CVE-2026-79991 | NA | N/A | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout … | 2026-09-02 |
| CVE-2026-81571 | MEDIUM | 4.8 | The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from be… | 2026-09-02 |
| CVE-2026-82293 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource con… | 2026-09-02 |
| CVE-2026-82884 | MEDIUM | 6.8 | The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts b… | 2026-09-02 |
| CVE-2026-82955 | NA | N/A | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD i… | 2026-09-02 |
| CVE-2026-83533 | MEDIUM | 5.3 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually … | 2026-09-02 |
| CVE-2026-83547 | MEDIUM | 6.8 | The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before ou… | 2026-09-02 |
| CVE-2026-8151 | MEDIUM | 5.4 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its set… | 2026-09-02 |
| CVE-2026-19820 | NA | N/A | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link… | 2026-09-01 |
| CVE-2026-18743 | LOW | 2.5 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration con… | 2026-09-01 |
| CVE-2026-48932 | LOW | 3.7 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that … | 2026-09-01 |
| CVE-2026-65643 | NA | N/A | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as… | 2026-09-01 |
| CVE-2026-67394 | NA | N/A | A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for … | 2026-09-01 |
| CVE-2026-67395 | MEDIUM | 5.9 | A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to imprope… | 2026-09-01 |
| CVE-2026-74837 | NA | N/A | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una… | 2026-09-01 |
| CVE-2026-75865 | CRITICAL | 9.8 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for W… | 2026-09-01 |
| CVE-2026-77856 | NA | N/A | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una… | 2026-09-01 |
| CVE-2026-77950 | NA | N/A | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow… | 2026-09-01 |
| CVE-2026-82730 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read … | 2026-09-01 |
| CVE-2026-82731 | NA | N/A | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an atta… | 2026-09-01 |
| CVE-2026-82732 | NA | N/A | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argum… | 2026-09-01 |
| CVE-2026-82733 | NA | N/A | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow… | 2026-09-01 |
| CVE-2026-19032 | MEDIUM | 5.3 | jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting t… | 2026-09-01 |
| CVE-2026-82734 | NA | N/A | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to subm… | 2026-09-01 |
| CVE-2026-82735 | NA | N/A | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive re… | 2026-09-01 |