Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-15290

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used t

PUBLISHED
Vendor
ultimatemember
Product
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-1529

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.9, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.13, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2.13, Red Hat build of Keycloak 26.4.9
Provider severity
HIGH
Conflicts
1

CVE-2026-15289

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. In

PUBLISHED
Vendor
wpdevart
Product
Booking calendar, Appointment Booking System
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15288

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and 'create_subscription_intent' functions without validating it against the form's configured price. This makes it possible for unauthenticated attackers to modify the payment amount to any arbitrary value w

PUBLISHED
Vendor
brainstormforce
Product
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator
Provider severity
HIGH
Conflicts
0

CVE-2026-15287

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive infor

PUBLISHED
Vendor
rtcamp
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15286

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and immediately publish posts of any type (including pages), bypassi

PUBLISHED
Vendor
stellarwp
Product
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15285

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passed the raw `custom_attributes` string through `tp_senitize_js_input()`. This filter is bypassable. The issue is patched in version 6.4.12.

PUBLISHED
Vendor
posimyththemes
Product
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15284

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quote characters) before storing the value in post meta, combined with missing output escaping in the king_addons_submissions_custom_column_content() function, which concatenates the s

PUBLISHED
Vendor
kingaddons
Product
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15283

The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_

PUBLISHED
Vendor
wpvividplugins
Product
WPvivid Backup for MainWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15282

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
tenteeglobal
Product
Instant Appointment
Provider severity
CRITICAL
Conflicts
0

CVE-2026-15280

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.

PUBLISHED
Vendor
IBM
Product
WebSphere Application Server - Liberty
Provider severity
HIGH
Conflicts
0

CVE-2026-1528

A flaw was found in undici. A remote attacker could exploit this vulnerability by sending a specially crafted WebSocket frame with an extremely large 64-bit length. This causes undici's ByteParser to overflow its internal calculations, leading to an invalid state and a fatal TypeError. The primary consequence is a Denial of Service (DoS), which terminates the process.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, undici, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Developer Hub 1.9, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.16, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Self-service automation portal 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform Expansion Pack, undici, Red Hat Developer Hub, Red Hat Enterprise Linux 10, Red Hat JBoss Enterprise Application Platform 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat OpenShift Dev Spaces, Red Hat OpenShift Dev Spaces, Red Hat OpenShift Pipelines 1.2, Red Hat OpenShift Dev Spaces 3.28, Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Developer Hub 1.8, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
2

CVE-2026-15276

A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

PUBLISHED
Vendor
pdeljanov
Product
Symphonia
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-15274

A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. The manipulation results in denial of service. The attack must be initiated from a local position. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.

PUBLISHED
Vendor
lo48576
Product
fbxcel
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-15271

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult.

PUBLISHED
Vendor
TOTOLINK, TOTOLINK, TOTOLINK, TOTOLINK, TOTOLINK, TOTOLINK, TOTOLINK
Product
CP450, EX200, A3100R, A950RG, AC1200T10, A3000RU, CS185R_T10
Provider severity
HIGH
Conflicts
3

CVE-2026-15270

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
D-link
Product
DIR-823G
Provider severity
HIGH
Conflicts
2

CVE-2026-1527

ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch) The vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters: // lib/dispatcher/client-h1.js:1121 if (upgrade) { heade

PUBLISHED
Vendor
undici
Product
undici
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15267

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query — the value is re-read at line 144 using only sanitize_text_field() (overwriting the earlier absint() result), then concatenated into the SQL WHERE clause as a

PUBLISHED
Vendor
taskbuilder
Product
Taskbuilder – Project Management & Task Management Tool With Kanban Board
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

PUBLISHED
Vendor
tenable
Product
tenable_agent
Provider severity
CRITICAL
Conflicts
2

CVE-2026-15262

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

PUBLISHED
Vendor
Unknown
Product
Admin Columns for ACF Fields
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15260

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

PUBLISHED
Vendor
Unknown
Product
GEO my WP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1526

A flaw was found in undici. A remote attacker can exploit this vulnerability by sending a specially crafted compressed frame, known as a "decompression bomb," during permessage-deflate decompression. The undici WebSocket client does not properly limit the size of decompressed data, leading to unbounded memory consumption. This can cause the Node.js process to exhaust available memory, resulting in a denial of service (DoS) where the process crashes or becomes unresponsive.

PUBLISHED
Vendor
undici, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
undici, Red Hat OpenShift AI 2.16, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Self-service automation portal 2, Red Hat OpenShift Pipelines 1.2, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.9, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Red Hat Developer Hub, Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux 10, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, OpenShift Lightspeed, Red Hat JBoss Enterprise Application Platform 8, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Developer Hub 1.8, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), OpenShift Pipelines
Provider severity
HIGH
Conflicts
2

CVE-2026-15258

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

PUBLISHED
Vendor
Unknown
Product
Product Feed Manager For WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-15257

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.

PUBLISHED
Vendor
Unknown
Product
RegistrationMagic
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15255

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.

PUBLISHED
Vendor
Unknown
Product
RegistrationMagic
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.

PUBLISHED
Vendor
Unknown
Product
Simply Schedule Appointments
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15252

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.

PUBLISHED
Vendor
Unknown
Product
Search Atlas SEO
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15250

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.

PUBLISHED
Vendor
Unknown
Product
Appointment Booking Plugin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1525

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: * Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays * Applications that accept user-controlled header names without case-normalization Potential conseque

PUBLISHED
Vendor
undici
Product
undici
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15248

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

PUBLISHED
Vendor
Unknown
Product
Meta Box
Provider severity
Not asserted
Conflicts
0

CVE-2026-15244

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inclusion path, allowing users with the shop manager capability to cause the inclusion and execution of arbitrary local files, which is then triggered on every front-end request including for unauthenticated visitors.

PUBLISHED
Vendor
Unknown
Product
HUSKY
Provider severity
Not asserted
Conflicts
0

CVE-2026-15243

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim. 

PUBLISHED
Vendor
Apereo, Apereo
Product
Java Apereo CAS Client, Jasig CAS Client
Provider severity
HIGH
Conflicts
1

CVE-2026-15241

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.

PUBLISHED
Vendor
Unknown
Product
AI ChatBot for WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.

PUBLISHED
Vendor
Unknown
Product
Customer Switching
Provider severity
HIGH
Conflicts
1

CVE-2026-1524

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also provide authorization. This edgecase becomes a security problem only if the authentication-only provider

PUBLISHED
Vendor
neo4j
Product
Enterprise Edition
Provider severity
LOW
Conflicts
1

CVE-2026-15236

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

PUBLISHED
Vendor
Unknown
Product
Gallery for Google Photos
Provider severity
HIGH
Conflicts
1

CVE-2026-15235

The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.

PUBLISHED
Vendor
Unknown
Product
MotoPress Hotel Booking
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15234

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

PUBLISHED
Vendor
Unknown
Product
Codeless Page Builder
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15231

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.

PUBLISHED
Vendor
Unknown
Product
Tag, Category, and Taxonomy Manager
Provider severity
Not asserted
Conflicts
0

CVE-2026-1523

Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker to access arbitrary files in the server's file system, thet is, 'http://<host>/..%2F..% 2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd'. By manipulating the input to include URL encoded directory traversal sequences (e.g., %2F representing /), an attacker can bypass the input validation mechanisms ans retrieve sensitive files outside the intended

PUBLISHED
Vendor
PRIMION DIGITEK, PRIMION DIGITEK
Product
Digitek DT950, Digitek ADT1100
Provider severity
HIGH
Conflicts
1

CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and haltin

PUBLISHED
Vendor
Not asserted
Product
Not asserted
Provider severity
HIGH
Conflicts
1

CVE-2026-15227

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

PUBLISHED
Vendor
Checkmk GmbH
Product
Checkmk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-15226

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid proper

PUBLISHED
Vendor
Canonical, Canonical, Canonical, Canonical, Canonical, Canonical
Product
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 16.04 LTS, Ubuntu 26.04 LTS
Provider severity
HIGH
Conflicts
1

CVE-2026-1522

A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_bearer_response of the file src/sgwc/s5c-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called b19cf6a. Applying a patch is advised to resolve this issue. The issue report is flagged as already-fixed.

PUBLISHED
Vendor
n/a
Product
Open5GS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15212

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-

PUBLISHED
Vendor
wpo365
Product
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Provider severity
HIGH
Conflicts
0

CVE-2026-1521

A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_failure_indication of the file src/sgwc/s5c-handler.c of the component SGWC. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The patch is named 69b53add90a9479d7960b822fc60601d659c328b. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
n/a
Product
Open5GS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

PUBLISHED
Vendor
Unknown
Product
JS Help Desk
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15206

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.

PUBLISHED
Vendor
Unknown
Product
SMS Alert
Provider severity
HIGH
Conflicts
1

CVE-2026-15204

A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.

PUBLISHED
Vendor
TOTOLINK
Product
X5000R
Provider severity
MEDIUM
Conflicts
1

CVE-2026-15202

A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
YzmCMS
Provider severity
MEDIUM
Conflicts
2