Sun, Sep 13 · 09:17 PM CDTCVE-2026-81648
10.0/10 · Must read/watchNVDvuln
Summary
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wal
CVECVE-2026-81648
SeverityCRITICAL
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT
Sat, Sep 12 · 03:16 AM CDTCVE-2026-85706
10.0/10 · Must read/watchNVDvuln
Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement
CVECVE-2026-85706
SeverityCRITICAL
TypeUPDATED
PublishedSat, Sep 12 · 03:16 AM CDT
ModifiedMon, Sep 14 · 10:59 AM CDT
Fri, Aug 28 · 04:18 PM CDTCVE-2026-81578
9.8/10 · Must read/watchNVDvuln
Summary
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated re
CVECVE-2026-81578
SeverityCRITICAL
TypeUPDATED
PublishedFri, Aug 28 · 04:18 PM CDT
ModifiedMon, Sep 14 · 12:16 AM CDT
Fri, Aug 28 · 04:18 PM CDTCVE-2026-82078
9.1/10 · Must read/watchNVDvuln
Summary
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuratio
CVECVE-2026-82078
SeverityCRITICAL
TypeUPDATED
PublishedFri, Aug 28 · 04:18 PM CDT
ModifiedMon, Sep 14 · 12:16 AM CDT
Sun, Sep 13 · 09:17 PM CDTCVE-2026-74933
8.8/10 · Worth your timeNVDvuln
Summary
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.
CVECVE-2026-74933
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT
Sun, Sep 13 · 09:17 PM CDTCVE-2026-85129
8.8/10 · Worth your timeNVDvuln
Summary
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone v
CVECVE-2026-85129
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT
Sun, Sep 13 · 09:17 PM CDTCVE-2026-88793
8.8/10 · Worth your timeNVDvuln
Summary
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execu
CVECVE-2026-88793
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90770
8.8/10 · Worth your timeNVDvuln
Summary
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbi
CVECVE-2026-90770
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Sun, Sep 13 · 12:17 PM CDTCVE-2026-90777
8.8/10 · Worth your timeNVDvuln
Summary
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.
CVECVE-2026-90777
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 12:17 PM CDT
ModifiedSun, Sep 13 · 12:17 PM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90561
8.7/10 · Worth your timeNVDvuln
Summary
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's
CVECVE-2026-90561
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Sun, Sep 13 · 11:16 AM CDTCVE-2026-90510
8.3/10 · Worth your timeNVDvuln
Summary
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipula
CVECVE-2026-90510
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:16 AM CDT
ModifiedSun, Sep 13 · 11:16 AM CDT
Sun, Sep 13 · 09:17 PM CDTCVE-2026-37008
8.1/10 · Worth your timeNVDvuln
Summary
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library wit
CVECVE-2026-37008
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90562
8.1/10 · Worth your timeNVDvuln
Summary
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
CVECVE-2026-90562
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90768
8.1/10 · Worth your timeNVDvuln
Summary
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership v
CVECVE-2026-90768
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Sun, Sep 13 · 01:16 PM CDTCVE-2026-90783
7.8/10 · Worth your timeNVDvuln
Summary
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is
CVECVE-2026-90783
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 01:16 PM CDT
ModifiedSun, Sep 13 · 01:16 PM CDT
Sun, Sep 13 · 08:16 PM CDTCVE-2026-29811
7.7/10 · Worth your timeNVDvuln
Summary
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CVECVE-2026-29811
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 08:16 PM CDT
ModifiedSun, Sep 13 · 08:16 PM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90769
7.7/10 · Worth your timeNVDvuln
Summary
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application se
CVECVE-2026-90769
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Tue, Jul 28 · 05:16 PM CDTCVE-2026-16313
7.6/10 · Worth your timeNVDvuln
Summary
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This
CVECVE-2026-16313
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 28 · 05:16 PM CDT
ModifiedMon, Sep 14 · 06:16 AM CDT
Mon, Aug 10 · 03:16 AM CDTCVE-2026-19387
7.6/10 · Worth your timeNVDvuln
Summary
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to applicati
CVECVE-2026-19387
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 10 · 03:16 AM CDT
ModifiedMon, Sep 14 · 05:16 AM CDT
Sun, Sep 13 · 11:17 AM CDTCVE-2026-90772
7.6/10 · Worth your timeNVDvuln
Summary
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing J
CVECVE-2026-90772
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:17 AM CDT
ModifiedSun, Sep 13 · 11:17 AM CDT
Sun, Sep 13 · 11:16 PM CDTCVE-2026-15891
7.5/10 · Worth your timeNVDvuln
Summary
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retain
CVECVE-2026-15891
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 11:16 PM CDT
ModifiedSun, Sep 13 · 11:16 PM CDT
Thu, Sep 03 · 01:06 PM CDTCVE-2026-85150
7.5/10 · Worth your timeNVDvuln
Summary
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow,
CVECVE-2026-85150
SeverityHIGH
TypeUPDATED
PublishedThu, Sep 03 · 01:06 PM CDT
ModifiedMon, Sep 14 · 06:16 AM CDT
Sun, Sep 13 · 06:16 AM CDTCVE-2026-86406
7.5/10 · Worth your timeNVDvuln
Summary
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan w
CVECVE-2026-86406
SeverityHIGH
TypeUPDATED
PublishedSun, Sep 13 · 06:16 AM CDT
ModifiedSun, Sep 13 · 11:16 AM CDT
Mon, Sep 07 · 02:16 PM CDTCVE-2026-86452
7.5/10 · Worth your timeNVDvuln
Summary
Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format.
CVECVE-2026-86452
SeverityHIGH
TypeUPDATED
PublishedMon, Sep 07 · 02:16 PM CDT
ModifiedMon, Sep 14 · 07:17 AM CDT
Sun, Sep 13 · 09:17 PM CDTCVE-2026-88802
7.5/10 · Worth your timeNVDvuln
Summary
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destro
CVECVE-2026-88802
SeverityHIGH
TypeNEW
PublishedSun, Sep 13 · 09:17 PM CDT
ModifiedSun, Sep 13 · 09:17 PM CDT