Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

PUBLISHED
Vendor
Unknown
Product
Event Booking Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.

PUBLISHED
Vendor
Unknown
Product
Event Booking Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actio

PUBLISHED
Vendor
Unknown
Product
Event Booking Manager for WooCommerce
Provider severity
Not asserted
Conflicts
0

CVE-2026-16060

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.

PUBLISHED
Vendor
Unknown
Product
Insert or Embed Articulate Content into WordPress
Provider severity
Not asserted
Conflicts
0

CVE-2026-1606

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16057

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.

PUBLISHED
Vendor
Unknown
Product
Contest Gallery
Provider severity
Not asserted
Conflicts
0

CVE-2026-1605

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Eclipse Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat build of Debezium 2, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Enterprise Linux 8, Red Hat Offline Knowledge Portal, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Fuse 7, OpenShift Developer Tools and Services, Red Hat AMQ Broker 7.14.0, Red Hat JBoss Enterprise Application Platform Expansion Pack, HawtIO HawtIO 4.4.0, Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Enterprise Linux 7, Eclipse Jetty, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Satellite 6, Red Hat OpenShift Dev Spaces 3.28, Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Web Server 6, streams for Apache Kafka 2, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Single Sign-On 7, Red Hat Data Grid 8, OpenShift Developer Tools and Services, Red Hat Enterprise Linux 9, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 2, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Enterprise Linux 8, Red Hat build of Apicurio Registry 3, OpenShift Developer Tools and Services, streams for Apache Kafka 3, Red Hat Enterprise Linux 9, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Provider severity
HIGH
Conflicts
2

CVE-2026-16042

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

PUBLISHED
Vendor
Unknown
Product
LWS Optimize
Provider severity
Not asserted
Conflicts
0

CVE-2026-1603

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

PUBLISHEDCISA KEV
Vendor
Ivanti
Product
Endpoint Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-1602

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16017

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed with the label "not planned".

PUBLISHED
Vendor
mosaxiv
Product
clawlet
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16016

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.

PUBLISHED
Vendor
poco-ai
Product
poco-claw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-16015

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.7 is able to resolve this issue. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. It is recommended to upgrade the affected component.

PUBLISHED
Vendor
poco-ai
Product
poco-claw
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16014

A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Hospital Bed Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16013

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affecte

PUBLISHED
Vendor
liftoff-sr
Product
CIPster
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1601

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Totolink
Product
A7000R
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16009

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16008

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.

PUBLISHED
Vendor
sagold
Product
json-schema-library
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16002

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.

PUBLISHED
Vendor
MZ Automation
Product
lib60870
Provider severity
HIGH
Conflicts
1

CVE-2026-1600

A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logic errors. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Bdtask
Product
Bhojon All-In-One Restaurant Management System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15997

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrust

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-LTS
Provider severity
LOW
Conflicts
0

CVE-2026-15995

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit report-related tasks simultaneously.

PUBLISHED
Vendor
IBM
Product
Cognos Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles. This makes it possi

PUBLISHED
Vendor
teydeastudio
Product
WP Password Policy
Provider severity
HIGH
Conflicts
0

CVE-2026-1599

A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument orggrandTotal/vat/service_charge/grandtotal can lead to business logic errors. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not re

PUBLISHED
Vendor
Bdtask
Product
Bhojon All-In-One Restaurant Management System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15988

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-based REST authentication bypass, granted they can trick a site administrator into performing an actio

PUBLISHED
Vendor
tigroumeow
Product
AI Engine – The Chatbot, AI Framework & MCP for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-15982

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.

PUBLISHED
Vendor
CodeRevolution
Product
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-15981

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing W

PUBLISHED
Vendor
cyberlord92
Product
SAML Single Sign On – SSO Login
Provider severity
CRITICAL
Conflicts
0

CVE-2026-1598

A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashboard/home/profile of the component User Information Module. Performing a manipulation of the argument fullname results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Bdtask
Product
Bhojon All-In-One Restaurant Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
HIGH
Conflicts
1

CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
HIGH
Conflicts
1

CVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
CRITICAL
Conflicts
1

CVE-2026-15975

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2026-15974

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15971

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1597

A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Bdtask
Product
SalesERP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
CRITICAL
Conflicts
1

CVE-2026-15968

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
HIGH
Conflicts
0

CVE-2026-15967

Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
HIGH
Conflicts
0

CVE-2026-15966

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

PUBLISHED
Vendor
Progress
Product
MOVEit Transfer
Provider severity
HIGH
Conflicts
0

CVE-2026-15964

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation and calling `reset_password()` on the resolved account without any ownership token, email confirmation

PUBLISHED
Vendor
britcoder
Product
Single Sign On For TNG
Provider severity
CRITICAL
Conflicts
0

CVE-2026-15962

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a

PUBLISHED
Vendor
techjewel
Product
Fluent Forms Pro Add On Pack
Provider severity
HIGH
Conflicts
0

CVE-2026-1596

A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
D-Link
Product
DWR-M961
Provider severity
MEDIUM
Conflicts
2

CVE-2026-15957

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow remote attackers to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a gen

PUBLISHED
Vendor
AWS
Product
aws-sdk-rust
Provider severity
HIGH
Conflicts
1

CVE-2026-15951

The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs() function, where each element of the `fields` array received from $_REQUEST['data'] is joined verbatim into the SELECT clause via implode() with no whitelist, escaping, or prepared-statem

PUBLISHED
Vendor
icegram
Product
Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15950

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an inje

PUBLISHED
Vendor
cozythemes
Product
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1595

A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-15945

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Single Sign-On 7
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15943

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat Single Sign-On 7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1594

A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of the argument detail leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-15939

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

PUBLISHED
Vendor
Unknown
Product
Simple Restrict
Provider severity
Not asserted
Conflicts
0