Sat, Sep 05 · 07:17 AM CDTCVE-2026-78362
9.8/10 · Must read/watchNVDvuln
Summary
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the S
CVECVE-2026-78362
SeverityCRITICAL
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Mon, Jul 20 · 08:16 AM CDTCVE-2026-16242
9.4/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could co
CVECVE-2026-16242
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 AM CDT
ModifiedSun, Sep 06 · 06:17 PM CDT
Sun, Sep 06 · 07:16 AM CDTCVE-2026-18480
8.8/10 · Worth your timeNVDvuln
Summary
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password re
CVECVE-2026-18480
SeverityHIGH
TypeUPDATED
PublishedSun, Sep 06 · 07:16 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Sun, Sep 06 · 04:16 PM CDTCVE-2026-19633
8.8/10 · Worth your timeNVDvuln
Summary
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with e
CVECVE-2026-19633
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 04:16 PM CDT
ModifiedSun, Sep 06 · 04:16 PM CDT
Mon, Jun 22 · 02:17 PM CDTCVE-2026-54099
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows wo
CVECVE-2026-54099
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 22 · 02:17 PM CDT
ModifiedSun, Sep 06 · 08:17 PM CDT
Sat, Sep 05 · 07:17 AM CDTCVE-2026-77826
8.8/10 · Worth your timeNVDvuln
Summary
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user reg
CVECVE-2026-77826
SeverityHIGH
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Sat, Sep 05 · 07:17 AM CDTCVE-2026-82304
8.6/10 · Worth your timeNVDvuln
Summary
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
CVECVE-2026-82304
SeverityHIGH
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Tue, Jul 28 · 01:18 PM CDTCVE-2026-49332
8.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated l
CVECVE-2026-49332
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 28 · 01:18 PM CDT
ModifiedSun, Sep 06 · 06:17 PM CDT
Mon, Jun 22 · 02:17 PM CDTCVE-2026-54100
8.3/10 · Worth your timeNVDvuln
Summary
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet boots
CVECVE-2026-54100
SeverityHIGH
TypeUPDATED
PublishedMon, Jun 22 · 02:17 PM CDT
ModifiedSun, Sep 06 · 08:17 PM CDT
Sun, Sep 06 · 12:17 PM CDTCVE-2026-86242
8.1/10 · Worth your timeNVDvuln
Summary
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the
CVECVE-2026-86242
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 12:17 PM CDT
ModifiedSun, Sep 06 · 12:17 PM CDT
Sat, Sep 05 · 07:17 AM CDTCVE-2026-84934
8.0/10 · Worth your timeNVDvuln
Summary
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a scr
CVECVE-2026-84934
SeverityHIGH
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Sat, Sep 05 · 07:17 AM CDTCVE-2026-84935
8.0/10 · Worth your timeNVDvuln
Summary
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser
CVECVE-2026-84935
SeverityHIGH
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Tue, Jun 17 · 01:15 PM CDTCVE-2025-6020
7.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CVECVE-2025-6020
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 17 · 01:15 PM CDT
ModifiedSun, Sep 06 · 08:17 PM CDT
Fri, Sep 04 · 09:17 AM CDTCVE-2026-81302
7.8/10 · Worth your timeNVDvuln
Summary
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
CVECVE-2026-81302
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 04 · 09:17 AM CDT
ModifiedMon, Sep 07 · 06:17 AM CDT
Wed, Aug 19 · 09:17 PM CDTCVE-2026-75569
7.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the
CVECVE-2026-75569
SeverityHIGH
TypeUPDATED
PublishedWed, Aug 19 · 09:17 PM CDT
ModifiedSun, Sep 06 · 07:17 PM CDT
Sun, Sep 06 · 12:17 PM CDTCVE-2022-51009
7.5/10 · Worth your timeNVDvuln
Summary
PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.
CVECVE-2022-51009
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 12:17 PM CDT
ModifiedSun, Sep 06 · 01:17 PM CDT
Sat, Sep 05 · 07:17 AM CDTCVE-2026-19858
7.5/10 · Worth your timeNVDvuln
Summary
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft con
CVECVE-2026-19858
SeverityHIGH
TypeUPDATED
PublishedSat, Sep 05 · 07:17 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Thu, Aug 27 · 05:18 PM CDTCVE-2026-5680
7.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denia
CVECVE-2026-5680
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 27 · 05:18 PM CDT
ModifiedMon, Sep 07 · 09:17 AM CDT
Sun, Sep 06 · 07:16 AM CDTCVE-2026-84219
7.5/10 · Worth your timeNVDvuln
Summary
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site wh
CVECVE-2026-84219
SeverityHIGH
TypeUPDATED
PublishedSun, Sep 06 · 07:16 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Sun, Sep 06 · 12:17 PM CDTCVE-2026-86250
7.5/10 · Worth your timeNVDvuln
Summary
h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.
CVECVE-2026-86250
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 12:17 PM CDT
ModifiedSun, Sep 06 · 12:17 PM CDT
Sun, Sep 06 · 01:17 PM CDTCVE-2026-86259
7.5/10 · Worth your timeNVDvuln
Summary
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
CVECVE-2026-86259
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 01:17 PM CDT
ModifiedSun, Sep 06 · 01:17 PM CDT
Fri, May 29 · 11:16 AM CDTCVE-2026-46579
7.4/10 · Worth your timeNVDvuln
Summary
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends rel
CVECVE-2026-46579
SeverityHIGH
TypeUPDATED
PublishedFri, May 29 · 11:16 AM CDT
ModifiedSun, Sep 06 · 06:17 PM CDT
Sun, Sep 06 · 11:18 AM CDTCVE-2026-86211
7.3/10 · Worth your timeNVDvuln
Summary
A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
CVECVE-2026-86211
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 11:18 AM CDT
ModifiedSun, Sep 06 · 11:18 AM CDT
Sun, Sep 06 · 01:17 PM CDTCVE-2026-86213
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has be
CVECVE-2026-86213
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 01:17 PM CDT
ModifiedSun, Sep 06 · 01:17 PM CDT
Sun, Sep 06 · 01:17 PM CDTCVE-2026-86214
7.3/10 · Worth your timeNVDvuln
Summary
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This
CVECVE-2026-86214
SeverityHIGH
TypeNEW
PublishedSun, Sep 06 · 01:17 PM CDT
ModifiedSun, Sep 06 · 01:17 PM CDT