| CVE-2026-82736 | NA | N/A | Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store… | 2026-09-01 |
| CVE-2026-82737 | NA | N/A | Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and c… | 2026-09-01 |
| CVE-2026-82738 | NA | N/A | Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a … | 2026-09-01 |
| CVE-2026-82739 | NA | N/A | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the st… | 2026-09-01 |
| CVE-2026-82740 | NA | N/A | Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a d… | 2026-09-01 |
| CVE-2026-82741 | NA | N/A | Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the s… | 2026-09-01 |
| CVE-2026-82742 | NA | N/A | Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by mat… | 2026-09-01 |
| CVE-2026-82743 | NA | N/A | Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a schedu… | 2026-09-01 |
| CVE-2026-82744 | NA | N/A | Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guar… | 2026-09-01 |
| CVE-2026-82745 | NA | N/A | Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record whe… | 2026-09-01 |
| CVE-2026-82746 | NA | N/A | Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource… | 2026-09-01 |
| CVE-2026-82748 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while c… | 2026-09-01 |
| CVE-2026-82749 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to… | 2026-09-01 |
| CVE-2026-12747 | MEDIUM | 6.4 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' S… | 2026-09-01 |
| CVE-2026-13203 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… | 2026-09-01 |
| CVE-2026-16787 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… | 2026-09-01 |
| CVE-2026-17589 | MEDIUM | 4.9 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'produ… | 2026-09-01 |
| CVE-2026-18752 | MEDIUM | 6.5 | The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie i… | 2026-09-01 |
| CVE-2026-19573 | HIGH | 7.2 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCom… | 2026-09-01 |
| CVE-2026-19796 | HIGH | 7.2 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to… | 2026-09-01 |
| CVE-2026-19806 | HIGH | 8.8 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPr… | 2026-09-01 |
| CVE-2026-19948 | MEDIUM | 5.3 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for… | 2026-09-01 |
| CVE-2026-19952 | HIGH | 7.5 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… | 2026-09-01 |
| CVE-2026-75921 | HIGH | 7.2 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder … | 2026-09-01 |
| CVE-2026-75965 | MEDIUM | 6.4 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for Word… | 2026-09-01 |
| CVE-2026-76006 | MEDIUM | 4.9 | The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injectio… | 2026-09-01 |
| CVE-2026-77823 | MEDIUM | 4.9 | The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_o… | 2026-09-01 |
| CVE-2026-82747 | NA | N/A | Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to … | 2026-09-01 |
| CVE-2026-83743 | MEDIUM | 6.3 | A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of th… | 2026-09-01 |
| CVE-2026-83744 | MEDIUM | 4.3 | A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability aff… | 2026-09-01 |
| CVE-2026-18488 | MEDIUM | 6.4 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block At… | 2026-09-01 |
| CVE-2026-75964 | MEDIUM | 6.1 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for Word… | 2026-09-01 |
| CVE-2026-75980 | MEDIUM | 6.4 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulne… | 2026-09-01 |
| CVE-2026-77189 | MEDIUM | 6.5 | The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)… | 2026-09-01 |
| CVE-2026-83772 | CRITICAL | 9.9 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue af… | 2026-09-01 |
| CVE-2026-78319 | NA | N/A | A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condit… | 2026-09-01 |
| CVE-2026-13611 | MEDIUM | 5.3 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints… | 2026-09-01 |
| CVE-2026-74916 | MEDIUM | 6.5 | The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters… | 2026-09-01 |
| CVE-2026-78363 | MEDIUM | 4.8 | The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being e… | 2026-09-01 |
| CVE-2026-15101 | MEDIUM | 6.4 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' par… | 2026-09-01 |
| CVE-2026-16786 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… | 2026-09-01 |
| CVE-2026-16788 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… | 2026-09-01 |
| CVE-2026-19914 | HIGH | 7.2 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order… | 2026-09-01 |
| CVE-2026-25706 | HIGH | 7.5 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who… | 2026-09-01 |
| CVE-2026-59680 | HIGH | 8.0 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of… | 2026-09-01 |
| CVE-2026-59681 | HIGH | 8.8 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory con… | 2026-09-01 |
| CVE-2026-4813 | NA | N/A | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticate… | 2026-09-01 |
| CVE-2026-82926 | MEDIUM | 5.5 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.
This issue … | 2026-09-01 |
| CVE-2026-82927 | MEDIUM | 5.5 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.
This i… | 2026-09-01 |
| CVE-2026-84059 | HIGH | 7.4 | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmA… | 2026-09-01 |