Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-9306

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about t

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-9305

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9304

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this

PUBLISHED
Vendor
calcom
Product
cal.diy
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-9303

A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
calcom
Product
cal.diy
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9302

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. Executing a manipulation of the argument vf can lead to code injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version inf

PUBLISHED
Vendor
546669204
Product
vps-inventory-monitoring
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9301

A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
omec-project
Product
amf
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9300

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue.

PUBLISHED
Vendor
omec-project
Product
amf
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9299

A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memory corruption. Remote exploitation of the attack is possible. The exploit has been published and may be used. Applying a patch is the recommended action to fix this issue.

PUBLISHED
Vendor
omec-project
Product
amf
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9298

A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The manipulation results in memory corruption. The attack may be launched remotely. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue.

PUBLISHED
Vendor
omec-project
Product
amf
Provider severity
MEDIUM
Conflicts
1

CVE-2026-9297

A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. The manipulation of the argument repeaterSSID leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
BR-6428NS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9296

A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2

PUBLISHED
Vendor
Edimax
Product
BR-6428NS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9295

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
BR-6428NS
Provider severity
HIGH
Conflicts
2

CVE-2026-9294

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
BR-6428NS
Provider severity
HIGH
Conflicts
2

CVE-2026-9292

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential th

PUBLISHED
Vendor
Rockwell Automation
Product
FactoryTalk® DataMosaix™ Private Cloud
Provider severity
HIGH
Conflicts
0

CVE-2026-9291

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.

PUBLISHED
Vendor
AWS
Product
Amazon Braket Python SDK
Provider severity
HIGH
Conflicts
1

CVE-2026-9290

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be

PUBLISHED
Vendor
wpusermanager
Product
WP User Manager – User Profile Builder & Membership
Provider severity
HIGH
Conflicts
0

CVE-2026-9284

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it

PUBLISHED
Vendor
woocommerce
Product
WooCommerce PayPal Payments
Provider severity
HIGH
Conflicts
0

CVE-2026-9282

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().

PUBLISHED
Vendor
boldgrid
Product
W3 Total Cache
Provider severity
HIGH
Conflicts
0

CVE-2026-9281

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a

PUBLISHED
Vendor
litonice13
Product
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9280

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that iframe mode (AI_OPTION_

PUBLISHED
Vendor
spacetime
Product
Ad Inserter – Ad Manager & AdSense Ads
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9279

Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, `grep`), the argument string is concatenated with the command and passed to `child_process.spawn` with the `shell: true` option, allowing shell metacharacters in the arguments to bypass the allowlist. An attacker with JavaScript execution in the renderer (e.g. via XSS or a malicious plugin) can execute arbitrary shell commands with the pri

PUBLISHED
Vendor
logseq
Product
logseq
Provider severity
HIGH
Conflicts
0

CVE-2026-9278

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PUBLISHED
Vendor
Unknown
Product
Form Builder CP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9277

A flaw was found in the shell-quote component. The quote() function did not properly validate object-token inputs, allowing line terminators to pass unescaped into the output. A remote attacker could exploit this vulnerability by providing specially crafted input, which a POSIX shell would interpret as a command separator. This could lead to command injection, enabling the attacker to execute arbitrary code on the system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Lightspeed, Red Hat Enterprise Linux 9, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Quay 3.15, OpenShift Pipelines, OpenShift Pipelines, Cluster Observability Operator 1.5.0, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Service Mesh 3.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Developer Hub 1.10, Node HealthCheck Operator, Red Hat Ansible Automation Platform 2, Cryostat 4, Red Hat Data Grid 8, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Container Platform 4.22, Cluster Observability Operator 1.5.0, Self-service automation portal 2, Red Hat Satellite 6.18, Cluster Observability Operator 1.5.0, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift AI (RHOAI), shell-quote, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 2.6, OpenShift Lightspeed, Red Hat Fuse 7, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Service Mesh 3.3, Red Hat Developer Hub 1.9, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.2, Red Hat build of Apache Camel - HawtIO 4, Red Hat Ansible Automation Platform 2, Gatekeeper 3, Red Hat Ansible Automation Platform 2, Cluster Observability Operator 1.5.0, Red Hat AMQ Broker 7, Red Hat OpenShift Service Mesh 3.1, Cluster Observability Operator 1.5.0, OpenShift Service Mesh 3, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux AI (RHEL AI) 3, Node HealthCheck Operator, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Cluster Observability Operator 1.5.0, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Dev Spaces, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Virtualization 4, Red Hat Quay 3.12, Red Hat OpenShift Service Mesh 3.2, Red Hat Migration Toolkit 1.8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Discovery 2, Cluster Observability Operator 1.5.0, Node HealthCheck Operator, Red Hat Build of Podman Desktop, Red Hat Quay 3.9, Red Hat OpenShift Container Platform 4, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Quay 3.1, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Service Mesh 2.6, Cryostat 4 on RHEL 9, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-9274

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private keys, Wi-Fi credentials and configuration data stored in RAM of the targeted device. Successful exploitation of this vulnerability could allow unauthorized access to encrypted com

PUBLISHED
Vendor
CP Plus
Product
Wi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9272

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.

PUBLISHED
Vendor
Progress Software
Product
Flowmon ADS
Provider severity
HIGH
Conflicts
0

CVE-2026-9271

Vulnerability Title

PUBLISHED
Vendor
Unknown
Product
KeepInMind Dashboard Notes
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9270

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta variable), allowing attackers to inject metrics, especially from methods that do not restrict the dat

PUBLISHED
Vendor
BINARY
Product
DataDog::DogStatsd
Provider severity
CRITICAL
Conflicts
1

CVE-2026-9269

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PUBLISHED
Vendor
Unknown
Product
Secure Copy Content Protection and Content Locking
Provider severity
LOW
Conflicts
0

CVE-2026-9267

Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a specific fragment_length value. Attackers can exploit missing buffer length validation before uint24 reads, memcmp, and memcpy operations during DTLS epoch 0 on both client and server paths to cause deni

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse tinydtls
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9266

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the devi

PUBLISHED
Vendor
Moxa
Product
UC-1200A Series
Provider severity
HIGH
Conflicts
0

CVE-2026-9265

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.

PUBLISHED
Vendor
JONASBN
Product
Crypt::OpenSSL::PKCS12
Provider severity
CRITICAL
Conflicts
0

CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.

PUBLISHED
Vendor
Trimble
Product
SketchUp
Provider severity
CRITICAL
Conflicts
1

CVE-2026-9263

The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per the Bluetooth specification a start segment (sc=0) always carries a 3-byte time_offset, so its segment-header len must be at least PDU_ISO_SEG_TIMEOFFSET_SIZE (3). isoal_check_seg_header() accepted start segments with len < 3 as valid, and isoal_rx_framed_consume() then computed length = seg_hdr->len - 3 in a uint8_t, underflow

PUBLISHED
Vendor
zephyrproject
Product
zephyr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9262

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

PUBLISHED
Vendor
Canon Inc., Canon Inc.
Product
EOS Network Setting Tool for Windows, EOS Network Setting Tool for macOS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-9261

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

PUBLISHED
Vendor
Canon Inc., Canon Inc.
Product
EOS Network Setting Tool for Windows, EOS Network Setting Tool for macOS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-9260

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

PUBLISHED
Vendor
Canon Inc., Canon Inc.
Product
EOS Network Setting Tool for macOS, EOS Network Setting Tool for Windows
Provider severity
MEDIUM
Conflicts
2

CVE-2026-9259

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

PUBLISHED
Vendor
Canon Inc., Canon Inc.
Product
EOS Network Setting Tool for macOS, EOS Network Setting Tool for Windows
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-9258

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

PUBLISHED
Vendor
Canon Inc., Canon Inc.
Product
EOS Network Setting Tool for macOS, EOS Network Setting Tool for Windows
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-9256

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, F5, Red Hat, Red Hat, Red Hat, Red Hat, F5, Red Hat, Red Hat
Product
Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, NGINX Plus, Red Hat Lightspeed proxy 1, Red Hat Discovery 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, NGINX Open Source, Red Hat Hardened Images, Red Hat Enterprise Linux 8
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-9255

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.

PUBLISHED
Vendor
AWS
Product
Kiro CLI
Provider severity
HIGH
Conflicts
1

CVE-2026-9253

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
loopus, loopus
Product
WP Cost Estimation & Payment Forms Builder, WP Cost Estimation & Payment Forms Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-9251

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9249

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
LOW
Conflicts
0

CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
LOW
Conflicts
0

CVE-2026-9247

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
LOW
Conflicts
0

CVE-2026-9246

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9245

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9243

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is placed into an unquoted HTML attribute (dir=) allowing attribute injection despite the use of esc_attr(). This makes it possible for authenticated attackers, with contributor-level acc

PUBLISHED
Vendor
posimyththemes
Product
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9242

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal IPN `callback` handler being registered as a nopriv AJAX action with no authentication or nonce requirement, and critically because the handler updates the payment log database row with attacker-controlled POST data — includ

PUBLISHED
Vendor
metagauss
Product
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Provider severity
MEDIUM
Conflicts
0

CVE-2026-9241

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled `$_REQUEST['wooc_order_user_roles']` parameter to determine the user's role context for role-based price resolution without any validation, allowing it to override the legitimate role data derived fr

PUBLISHED
Vendor
realmag777
Product
FOX – Currency Switcher Professional for WooCommerce
Provider severity
MEDIUM
Conflicts
0