Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

PUBLISHED
Vendor
Progress Software
Product
Telerik UI for ASP.NET AJAX
Provider severity
HIGH
Conflicts
0

CVE-2026-13183

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

PUBLISHED
Vendor
Progress Software
Product
Telerik UI for ASP.NET AJAX
Provider severity
HIGH
Conflicts
0

CVE-2026-13182

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

PUBLISHED
Vendor
Progress Software
Product
Telerik UI for ASP.NET AJAX
Provider severity
HIGH
Conflicts
0

CVE-2026-13181

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.

PUBLISHED
Vendor
Progress Software
Product
Telerik UI for ASP.NET AJAX
Provider severity
HIGH
Conflicts
0

CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

PUBLISHED
Vendor
Unknown
Product
Eventin
Provider severity
HIGH
Conflicts
1

CVE-2026-1317

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL queries without proper sanitization. This makes it possible for authenticated attackers with Subscriber-level access or higher to append additional SQL queries into already existing queries via a malicious

PUBLISHED
Vendor
smackcoders
Product
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13165

SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a malicious DLL/SO/DYLIB as a local-file-header entry between the last legitimate entry and the Central Directory, without adding it to the Central Directory. The signature verifier never sees the injected entry and accepts th

PUBLISHED
Vendor
Krajowa Izba Rozliczeniowa
Product
SzafirHost
Provider severity
HIGH
Conflicts
0

CVE-2026-13164

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended to be restricted, because the endpoint applies the AllowAny permission with no email verification, CAPTCHA, or administrator approval. Any account created this way can read all email stored by the instance, resulting in fu

PUBLISHED
Vendor
Mailerup
Product
Mailerup
Provider severity
HIGH
Conflicts
0

CVE-2026-13163

Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL scheme is validated (blocking javascript: and data:) but the destination host is not restricted to an allowlist, and a signing.BadSignature exception is silently caught so a valid sign

PUBLISHED
Vendor
Mailerup
Product
Mailerup
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13161

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from

PUBLISHED
Vendor
themetechmount
Product
TrueBooker – Appointment Booking and Scheduler System
Provider severity
HIGH
Conflicts
0

CVE-2026-1316

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is enabled) to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
ivole
Product
Customer Reviews for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-13158

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

PUBLISHED
Vendor
Unknown
Product
Everest Toolkit
Provider severity
Not asserted
Conflicts
0

CVE-2026-13157

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

PUBLISHED
Vendor
Unknown
Product
Theme Demo Import
Provider severity
Not asserted
Conflicts
0

CVE-2026-13156

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

PUBLISHED
Vendor
Unknown
Product
MailerSend
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13152

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.

PUBLISHED
Vendor
Unknown
Product
Custom Fields Account Registration For Woocommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 and lower allows remote attackers to make the server issue requests to arbitrary internal or external URLs, including cloud metadata services, and return the rendered content in the resulting PDF via a crafted Host header, because the target URL is built from request.base_url without validation.

PUBLISHED
Vendor
Pentestify
Product
Pentestify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1315

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
Tapo C520WS v2, Tapo C220 v1
Provider severity
HIGH
Conflicts
1

CVE-2026-13149

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.

PUBLISHED
Vendor
juliangruber
Product
brace-expansion
Provider severity
HIGH
Conflicts
1

CVE-2026-13147

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

PUBLISHED
Vendor
Unknown
Product
Kirki
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13145

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.

PUBLISHED
Vendor
Unknown
Product
WP Travel
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13143

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.

PUBLISHED
Vendor
Unknown
Product
WP Travel
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13142

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

PUBLISHED
Vendor
Unknown
Product
Social Login, Passkeys, Magic Link & Email OTP
Provider severity
HIGH
Conflicts
1

CVE-2026-13140

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e.

PUBLISHED
Vendor
Thinkst Applied Research
Product
Canarytokens
Provider severity
LOW
Conflicts
0

CVE-2026-1314

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to retrieve flipbook page metadata for draft, private and password-protected flipbooks.

PUBLISHED
Vendor
iberezansky
Product
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13132

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then

PUBLISHED
Vendor
GeoVision Inc.
Product
GeoWebPlayer
Provider severity
HIGH
Conflicts
0

CVE-2026-13131

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then

PUBLISHED
Vendor
GeoVision Inc.
Product
GeoWebPlayer
Provider severity
HIGH
Conflicts
0

CVE-2026-1313

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify in

PUBLISHED
Vendor
eagerterrier
Product
MimeTypes Link Icons
Provider severity
HIGH
Conflicts
0

CVE-2026-13129

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.

PUBLISHED
Vendor
Foxit Software Inc., Foxit Software Inc.
Product
Foxit PDF Reader, Foxit PDF Editor
Provider severity
HIGH
Conflicts
1

CVE-2026-13128

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.

PUBLISHED
Vendor
Foxit Software Inc., Foxit Software Inc.
Product
Foxit PDF Editor, Foxit PDF Reader
Provider severity
HIGH
Conflicts
1

CVE-2026-13127

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.

PUBLISHED
Vendor
Foxit Software Inc., Foxit Software Inc.
Product
Foxit PDF Editor, Foxit PDF Reader
Provider severity
HIGH
Conflicts
1

CVE-2026-13126

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.

PUBLISHED
Vendor
Foxit Software Inc., Foxit Software Inc.
Product
Foxit PDF Editor, Foxit PDF Reader
Provider severity
HIGH
Conflicts
1

CVE-2026-13125

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. In order to access the websocket server, no authentication is required. As such, any malicious website can attempt to open a connecti

PUBLISHED
Vendor
GeoVision Inc.
Product
GeoWebPlayer
Provider severity
HIGH
Conflicts
0

CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

PUBLISHED
Vendor
Openvpn
Product
OpenVPN
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1312

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, djangoproject, Red Hat, Red Hat, Red Hat
Product
Red Hat Satellite 6.17 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Red Hat OpenStack Platform 16.2, Red Hat Satellite 6.17 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.17 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.18, Red Hat Satellite 6.17 for RHEL 9, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.17 for RHEL 9, Red Hat Discovery 2, Red Hat Satellite 6.17 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.5, Red Hat OpenStack Platform 17.1, Red Hat Satellite 6.17 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Satellite 6.18 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Red Hat OpenStack Platform 18.0, Red Hat Satellite 6.17 for RHEL 9, Django, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.16 for RHEL 9
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-13119

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identif

PUBLISHED
Vendor
roundupwp
Product
Registrations for the Events Calendar – Event Registration Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

PUBLISHED
Vendor
OpenVPN
Product
OpenVPN
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13116

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to mint publicly accessible, session-free download links for arbitrary third-party orders, exposing customer names, billing and shipping addresses, email

PUBLISHED
Vendor
wpovernight
Product
PDF Invoices & Packing Slips for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13114

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
stylemix
Product
Motors – Car Dealership & Classified Listings Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-13113

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13110

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and only validates a nonce ('ajd_protected') that is emitted publicly via wp_localize_script() on every frontend page through front_scripts() . This makes it possible for unauthentica

PUBLISHED
Vendor
wedevs
Product
StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1311

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

PUBLISHED
Vendor
bearsthemes
Product
Worry Proof Backup
Provider severity
HIGH
Conflicts
0

CVE-2026-13104

A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.

PUBLISHED
Vendor
Lenovo
Product
App Store
Provider severity
HIGH
Conflicts
1

CVE-2026-13103

A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.

PUBLISHED
Vendor
Lenovo
Product
App Store
Provider severity
HIGH
Conflicts
1

CVE-2026-1310

The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.6. This is due to missing capability checks on the `miga_ajax_editor_cal_delete` function that is hooked to the `miga_editor_cal_delete` AJAX action with both authenticated and unauthenticated access enabled. This makes it possible for unauthenticated attackers to delete arbitrary calendar entries by sending a request with a valid nonce and the calendar entry ID

PUBLISHED
Vendor
migaweb
Product
Simple calendar for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13089

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the clai

PUBLISHED
Vendor
RITOU
Product
OIDC::Lite
Provider severity
HIGH
Conflicts
0

CVE-2026-13084

A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0

CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.

PUBLISHED
Vendor
Red Hat, Red Hat
Product
Pen Drive Powered by Red Hat Lightspeed, Pen Drive Powered by Red Hat Lightspeed
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13082

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The built-in rand function is unsuitable for security applications because it is predictable and reversible.

PUBLISHED
Vendor
BURAK
Product
GD::SecurityImage
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13080

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or

PUBLISHED
Vendor
getwpfunnels
Product
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13079

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0