CVE IDSeverityCVSSDescriptionDate
CVE-2026-82736NAN/AIncorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store…2026-09-01
CVE-2026-82737NAN/AInteger Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and c…2026-09-01
CVE-2026-82738NAN/AImproper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a …2026-09-01
CVE-2026-82739NAN/AGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the st…2026-09-01
CVE-2026-82740NAN/AImproper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a d…2026-09-01
CVE-2026-82741NAN/AImproper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the s…2026-09-01
CVE-2026-82742NAN/AUncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by mat…2026-09-01
CVE-2026-82743NAN/AUncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a schedu…2026-09-01
CVE-2026-82744NAN/ANot Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guar…2026-09-01
CVE-2026-82745NAN/AImproper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record whe…2026-09-01
CVE-2026-82746NAN/AMissing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource…2026-09-01
CVE-2026-82748NAN/AIncorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while c…2026-09-01
CVE-2026-82749NAN/AIncorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to…2026-09-01
CVE-2026-12747MEDIUM6.4The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' S…2026-09-01
CVE-2026-13203MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…2026-09-01
CVE-2026-16787MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…2026-09-01
CVE-2026-17589MEDIUM4.9The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'produ…2026-09-01
CVE-2026-18752MEDIUM6.5The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie i…2026-09-01
CVE-2026-19573HIGH7.2The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCom…2026-09-01
CVE-2026-19796HIGH7.2The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to…2026-09-01
CVE-2026-19806HIGH8.8The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPr…2026-09-01
CVE-2026-19948MEDIUM5.3The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for…2026-09-01
CVE-2026-19952HIGH7.5The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic…2026-09-01
CVE-2026-75921HIGH7.2The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder …2026-09-01
CVE-2026-75965MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for Word…2026-09-01
CVE-2026-76006MEDIUM4.9The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injectio…2026-09-01
CVE-2026-77823MEDIUM4.9The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_o…2026-09-01
CVE-2026-82747NAN/AIncorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to …2026-09-01
CVE-2026-83743MEDIUM6.3A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of th…2026-09-01
CVE-2026-83744MEDIUM4.3A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability aff…2026-09-01
CVE-2026-18488MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block At…2026-09-01
CVE-2026-75964MEDIUM6.1The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for Word…2026-09-01
CVE-2026-75980MEDIUM6.4The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulne…2026-09-01
CVE-2026-77189MEDIUM6.5The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)…2026-09-01
CVE-2026-83772CRITICAL9.9A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue af…2026-09-01
CVE-2026-78319NAN/AA service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condit…2026-09-01
CVE-2026-13611MEDIUM5.3The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints…2026-09-01
CVE-2026-74916MEDIUM6.5The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters…2026-09-01
CVE-2026-78363MEDIUM4.8The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being e…2026-09-01
CVE-2026-15101MEDIUM6.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' par…2026-09-01
CVE-2026-16786MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…2026-09-01
CVE-2026-16788MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…2026-09-01
CVE-2026-19914HIGH7.2The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order…2026-09-01
CVE-2026-25706HIGH7.5Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who…2026-09-01
CVE-2026-59680HIGH8.0An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of…2026-09-01
CVE-2026-59681HIGH8.8A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory con…2026-09-01
CVE-2026-4813NAN/AA vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticate…2026-09-01
CVE-2026-82926MEDIUM5.5NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue …2026-09-01
CVE-2026-82927MEDIUM5.5Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This i…2026-09-01
CVE-2026-84059HIGH7.4A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmA…2026-09-01
6 / 7715