Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-16735

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
release-it
Product
conventional-changelog
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16733

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
bahmutov
Product
find-cypress-specs
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16730

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1673

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for unauthenticated attackers to delete WooCommerce taxonomy terms (categories, tags, etc.) via a forged request granted they can trick a site administrator or shop manager into performing an actio

PUBLISHED
Vendor
realmag777
Product
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16729

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the call

PUBLISHED
Vendor
undici
Product
undici
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16728

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a partial response with a mismatched framing header, close the socket early, and have the retry interceptor assemble a body of a different length while the original Content-Length sta

PUBLISHED
Vendor
undici
Product
undici
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16727

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS
Product
Armoury Crate
Provider severity
HIGH
Conflicts
0

CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

PUBLISHED
Vendor
Alibaba
Product
Fastjson
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1672

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_redraw_table_row() function. This makes it possible for unauthenticated attackers to update WooCommerce product data including prices, descriptions, and other product fields via a forged request granted they can trick a site administrator or shop m

PUBLISHED
Vendor
realmag777
Product
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1671

The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view potentially sensitive information (e.g., the password of a higher level user, such as an administrator) contained in the exposed log files.

PUBLISHED
Vendor
switcorp
Product
Activity Log for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1670

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

PUBLISHED
Vendor
Honeywell, Honeywell, Honeywell, Honeywell
Product
PTZ WDR 2MP 32M, 25M IPC, SMB NDAA MVO-3, I-HIB2PI-UL 2MP IP
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

PUBLISHED
Vendor
Red Hat, Google, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Keras, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-16685

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content

PUBLISHED
Vendor
codename065
Product
Download Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16684

The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
mervb1
Product
Easy Property Listings
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1668

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc.
Product
SG3210XHP-M2 3.x, SG2008P 3.3x, SG2218P 1.2x, SG3452P 3.4x, SG3210X-M2 1.x, SG3428XF 1.2x, SG3428XF 1.3x, SG2016P 1.3x, SG2218P 2.x, SG2210P 5.3x, SG3428XMPP 1.2x, SG3452 1.3x, SG2008 4.3x, SX3016F 1.3x, SG2210MP 4.2x, SG2005P-PD 1.x, SG2210XMP-M2 1.x, SG2428P 5.2x, SG3428MP 6.3x, SG2452LP 1.x, SX3206HPP 1.20, SG3452P 3.3x, SG3452 1.2x, SG3428MP 6.2x, SX3832MPP 1.x, SG3452X 1.2x, SG3428XMPP 1.x, SG3210 3.3x, SG2210P 5.2x, SG3428XMP 3.2x, SX3032F 1.x, SG3428X 1.4x, SG3210X-M2 1.2x, SG3210 3.2x, SG3428 2.3x, SX3832 1.x, SG2428LP 1.x, SG3428XMP 3.3x, SG2210MP 5.x, SG2218 1.2x, SG2016P 1.2x, SG3452X 1.3x, SG2008 4.2x, SG3452XMPP 1.x, SG2210MP 5.2x, SL2428P 6.2x, SG2218 1.3x, SG2008P 3.2x, SG3428X-M2 1.2x, SG3218XP-M2 1.x, SG3428XPP-M2 1.2x, SX3008F 1.2x, TL-SG3452P 3.0, TL-SG2428P 4.x, SG2428P 5.3x, SG3428X 1.3x, SG3452XP 2.3x, SG2218P 2.2x, TL-SG3428MP 5.x, SG3428 2.4x, SG3452XP 2.2x, SX3016F 1.2x
Provider severity
HIGH
Conflicts
1

CVE-2026-1667

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected

PUBLISHED
Vendor
cifi
Product
GEO Plugin by Squirrly SEO
Provider severity
HIGH
Conflicts
0

CVE-2026-1666

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
codename065
Product
Download Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16655

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wpmanageninja
Product
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-16653

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
boazsegev
Product
facil.io
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1665

A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wget commands, and the NVM_AUTH_HEADER environment variable was not sanitized in the wget code path (though it was sanitized in the curl code path). An attacker who can set environment variables in a victim's shell environment (e.g., via malicious CI/CD configurations, compromised dotfiles, or Docker images) can inject arbitrary shell commands that ex

PUBLISHED
Vendor
nvm-sh
Product
nvm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1664

Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive the target agentName and agentId without proper validation or origin checks, allowing an external attacker with control of these headers to route inbound mail to arbitrary Durable Object instances and namespaces . Root cause The `createHeaderBasedEmailResol

PUBLISHED
Vendor
Not asserted
Product
Not asserted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain which roles can be assigned. This makes it possible for authenticated attackers, with Subscriber-level a

PUBLISHED
Vendor
pronamic
Product
Pronamic Pay
Provider severity
HIGH
Conflicts
0

CVE-2026-16634

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document. TOML::XS version 0.06 or later uses the successor tomlc17 library.

PUBLISHED
Vendor
FELIPE
Product
TOML::XS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16632

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
boazsegev
Product
facil.io
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-16631

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used. The patch is identified as adf2d9a09945fc98c85a2520a89f441d78b2dbd8. It is advisable to implement a patch to correct this issue. The project maintainer explains: "I think it's very rare for some

PUBLISHED
Vendor
n/a
Product
publint
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16630

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
syncfusion
Product
ej2-javascript-ui-controls
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1663

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16629

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.

PUBLISHED
Vendor
danger
Product
danger-js
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16628

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible with local access. The exploit is now public and may be used. The patch is named 939b045725e065baebc4587b8bccfd56731eed3d. To fix this issue, it is recommended to deploy a patch.

PUBLISHED
Vendor
n/a
Product
oclif
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.

PUBLISHED
Vendor
Cal.com
Product
Cal.diy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1662

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAut

PUBLISHED
Vendor
GNOME, Red Hat
Product
librest, Red Hat Enterprise Linux 10
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16614

The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 5.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extr

PUBLISHED
Vendor
westerndeal
Product
GSheetConnector – CF7 Google Sheets Connector
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitizati

PUBLISHED
Vendor
ASE
Product
Admin and Site Enhancements (ASE) Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-16607

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.

PUBLISHED
Vendor
Fujitsu, Fujitsu
Product
Oracle Solaris openFT, Linux openFT
Provider severity
HIGH
Conflicts
2

CVE-2026-16606

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.

PUBLISHED
Vendor
Fujitsu, Fujitsu
Product
Oracle Solaris openFT, Linux openFT
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1660

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16597

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_

PUBLISHED
Vendor
duracelltomi
Product
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-1659

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2026-16587

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submissio

PUBLISHED
Vendor
nasirahmed
Product
Advanced Form Integration — Connect Forms to 200+ Apps
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16585

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Th

PUBLISHED
Vendor
wordplus
Product
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
Provider severity
HIGH
Conflicts
0

CVE-2026-16584

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users sh

PUBLISHED
Vendor
AWS
Product
aws-api-mcp-server
Provider severity
HIGH
Conflicts
1

CVE-2026-16581

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

PUBLISHED
Vendor
igloohome
Product
Smart Lock Mobile Application
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1658

User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from 20.4.1 through 25.2.

PUBLISHED
Vendor
OpenText™
Product
Directory Services
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.

PUBLISHED
Vendor
Unknown
Product
LogMyTrip
Provider severity
HIGH
Conflicts
1

CVE-2026-1657

The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification despite a nonce being created. This makes it possible for unauthenticated attackers to upload image files to the WordPress uploads directory and create Media Library attachments v

PUBLISHED
Vendor
metagauss
Product
EventPrime – Events Calendar, Bookings and Tickets
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16565

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.

PUBLISHED
Vendor
Unknown
Product
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16564

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.

PUBLISHED
Vendor
Unknown
Product
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16563

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.

PUBLISHED
Vendor
Unknown
Product
Academy LMS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16560

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 8, Red Hat Directory Server 11, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6
Provider severity
MEDIUM
Conflicts
1