Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-8669

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such chec

PUBLISHED
Vendor
TONYC
Product
Imager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8668

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.

PUBLISHED
Vendor
Progress Chef
Product
Chef360
Provider severity
LOW
Conflicts
0

CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Traceroute Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect TR Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Finger Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect RPM Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8662

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Compression Plugin
Provider severity
LOW
Conflicts
0

CVE-2026-8661

Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial fix in 4.0.0 disabled JavaScript but did not neutralize resource-loading vectors. Resolved in 4.0.2 by sanitizing HTML with an allowlist of tags, attributes, and URL schemes.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Markdown Plugin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Ping Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect SQLmap Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction.

PUBLISHED
Vendor
Rapid7
Product
InsightConnect Tcpdump Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8657

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of Object.prototype.

PUBLISHED
Vendor
n/a, n/a
Product
org.webjars.npm:jsondiffpatch, jsondiffpatch
Provider severity
HIGH
Conflicts
3

CVE-2026-8656

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML can be interpreted by the browser, resulting in XSS.

PUBLISHED
Vendor
n/a
Product
jsondiffpatch
Provider severity
MEDIUM
Conflicts
2

CVE-2026-8655

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment

PUBLISHED
Vendor
NetScaler, NetScaler
Product
Gateway, ADC
Provider severity
HIGH
Conflicts
1

CVE-2026-8654

Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.

PUBLISHED
Vendor
Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data, Delphix Continuous data
Product
Cassandra Connector, SAP HANA Connector, Oracle EBS Connector, IBM Db2 Connector, Oracle Backup Ingestion Connector, CockroachDB Connector, Couchbase Connector, YugabyteDB Connector, MySQL Connector, MSSQL on Linux Connector, MangoDB Connector, PostgreSQL Connector
Provider severity
HIGH
Conflicts
1

CVE-2026-8653

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access or above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the dat

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8652

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

PUBLISHED
Vendor
NEC Platforms, Ltd., NEC Platforms, Ltd.
Product
Aterm MR51FN, Aterm CM51FD
Provider severity
HIGH
Conflicts
1

CVE-2026-8651

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
LOW
Conflicts
0

CVE-2026-8650

Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8649

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8647

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available.

PUBLISHED
Vendor
MIK
Product
Crypt::ScryptKDF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

PUBLISHED
Vendor
IBM, IBM
Product
WebSphere Application Server - Liberty, WebSphere Application Server
Provider severity
HIGH
Conflicts
1

CVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

PUBLISHED
Vendor
IBM
Product
WebSphere Application Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Python Packaging Authority, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.4, Migration Toolkit for Applications 8, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat Hardened Images, Red Hat OpenShift AI 3.0, OpenShift Service Mesh 3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI 3.0, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI (RHOAI), Pen Drive Powered by Red Hat Lightspeed, Red Hat AI Inference Server, Red Hat OpenShift AI 3.0, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Exploit Intelligence, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Enterprise Linux 10, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux 7, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI 3.4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.2, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat Trusted Artifact Signer 1.4, Service Telemetry Framework 1.5, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Service Telemetry Framework 1.5, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Migration Toolkit for Virtualization, Red Hat Quay 3, Migration Toolkit for Virtualization, Red Hat Discovery 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), pip, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI 3.2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Service Telemetry Framework 1.5, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 2.25, Red Hat Satellite 6, Red Hat OpenShift AI 3.4, Red Hat Enterprise Linux 8, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 3.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI 3.4, Red Hat Developer Hub, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.4, Red Hat AI Inference Server, Red Hat OpenShift AI 3.2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer, Red Hat AI Inference Server, Red Hat Enterprise Linux 10, Red Hat AI Inference Server, Red Hat OpenShift AI 3.0, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-8637

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.

PUBLISHED
Vendor
Lenovo
Product
LanSchool Classic
Provider severity
HIGH
Conflicts
1

CVE-2026-8636

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

PUBLISHED
Vendor
IBM, IBM
Product
Datacap, Datacap Navigator
Provider severity
MEDIUM
Conflicts
1

CVE-2026-8635

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-8634

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote envi

PUBLISHED
Vendor
openclaw
Product
crabbox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

PUBLISHED
Vendor
IBM
Product
Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty
Provider severity
CRITICAL
Conflicts
0

CVE-2026-8632

A flaw was found in the HP Linux Imaging and Printing Software (HPLIP). This vulnerability may allow a local attacker to achieve escalation of privileges and/or arbitrary code execution through operating system command injection. This could lead to an attacker gaining unauthorized control over the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, HP Inc, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, HP Linux Imaging and Printing Software, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Provider severity
HIGH
Conflicts
3

CVE-2026-8631

A flaw was found in HP Linux Imaging and Printing Software (HPLIP). An integer overflow in the hpcups processing path when handling crafted print data may lead to arbitrary code execution or privilege escalation on the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, HP Inc, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, HP Linux Imaging and Printing Software, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9
Provider severity
CRITICAL
Conflicts
3

CVE-2026-8629

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions

PUBLISHED
Vendor
openclaw
Product
crabbox
Provider severity
HIGH
Conflicts
1

CVE-2026-8628

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The payload is delivered via attacker-controlled path-info in the URL (e.g., /wp-admin/

PUBLISHED
Vendor
owencutajar
Product
EntreDroppers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8627

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_page() function echoing $_SERVER['PHP_SELF'] into a form's action attribute without any input sanitization or output escaping (such as esc_url() or esc_attr()). Because PHP_SELF reflects attacker-controlled path-info appended to the script URL, an attacker can break out of the attribute and inject arbi

PUBLISHED
Vendor
lykich
Product
Correct Prices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8626

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The PHP_SELF value is reflected in two separate locations within the vulnerable function —

PUBLISHED
Vendor
owencutajar
Product
SponsorMe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8624

The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability arises specifically because PHP_SELF includes attacke

PUBLISHED
Vendor
etspring
Product
LJ comments import: reloaded
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8622

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected payload only executes in the context of an administrator, as t

PUBLISHED
Vendor
pixelwelt
Product
Image Sizes on Demand
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8621

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts.

PUBLISHED
Vendor
openclaw
Product
crabbox
Provider severity
HIGH
Conflicts
1

CVE-2026-8620

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

PUBLISHED
Vendor
IBM
Product
Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty
Provider severity
HIGH
Conflicts
0

CVE-2026-8617

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both of which are exposed to unauthenticated users through the wp_ajax_nopriv_ hooks. This makes it possible for unauthenticated attackers to overwrite or delete the plugin's stored acc

PUBLISHED
Vendor
ailchev
Product
SearchPlus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8616

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible

PUBLISHED
Vendor
devozon
Product
Fense Proxy & VPN Blocker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8614

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's options including the critical 'assistiobot_oauth_settings' option, which disrupts the plugin's integration with the Assistio bot servi

PUBLISHED
Vendor
assistioai
Product
Assistio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8613

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This affects the Posts Timeline widget as well as the Posts Carousel wi

PUBLISHED
Vendor
smub
Product
aThemes Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8612

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constructs a default Cache::FileCache under /tmp/FileCache without overriding the backend's documented directory_umask of 000, so the cache root and its subdirectories are created mode 0777 with no sticky bit. Cache entries are named by sha1_hex of the request and rea

PUBLISHED
Vendor
OALDERS
Product
WWW::Mechanize::Cached
Provider severity
MEDIUM
Conflicts
1

CVE-2026-8611

The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4 via the 'invoice_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary customer invoices by enumerating sequential post IDs, exposing sensitive billing PII including full name, email address, phone number, order total, line it

PUBLISHED
Vendor
klamra22
Product
Klamra Paycal for Aspaclaria
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8610

The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the plugin's site-wide font settings, including the typesquare_auth option (fontThemeUseType), show_post_form, and typesquare_fonttheme, by submitting a POST requ

PUBLISHED
Vendor
conoha
Product
TypeSquare Webfonts for ConoHa
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

PUBLISHED
Vendor
Grafana
Product
Grafana OSS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-8608

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied payment data — including transaction ID, amount, and payment status — without performing any server-side verification against the PayPal API or any other payment gateway, and without no

PUBLISHED
Vendor
awordpresslife
Product
Event Monster – Event Manager, Ticket Booking & Registration
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
saadiqbal
Product
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-8606

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, including signing secrets and private keys. Exploitation required GitHub Packages to be enabled; on instanc

PUBLISHED
Vendor
GitHub
Product
Enterprise Server
Provider severity
HIGH
Conflicts
0