| unknown |
CVE-2026-75589 — Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with… |
vulnerability |
nvd |
CVE-2026-75589 |
|
2026-08-19 |
| unknown |
CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verif… |
vulnerability |
nvd |
CVE-2026-72889 |
|
2026-08-19 |
| high |
CVE-2026-58088 — The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the cor… |
vulnerability |
nvd |
CVE-2026-58088 |
|
2026-08-19 |
| high |
CVE-2026-58087 — The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dro… |
vulnerability |
nvd |
CVE-2026-58087 |
|
2026-08-19 |
| unknown |
CVE-2026-58086 — As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed… |
vulnerability |
nvd |
CVE-2026-58086 |
|
2026-08-19 |
| critical |
CVE-2026-58085 — After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to ch… |
vulnerability |
nvd |
CVE-2026-58085 |
ransomware |
2026-08-19 |
| unknown |
CVE-2026-58084 — To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the curren… |
vulnerability |
nvd |
CVE-2026-58084 |
|
2026-08-19 |
| high |
CVE-2026-58083 — While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be… |
vulnerability |
nvd |
CVE-2026-58083 |
|
2026-08-19 |
| unknown |
CVE-2026-58082 — The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate char… |
vulnerability |
nvd |
CVE-2026-58082 |
|
2026-08-19 |
| unknown |
CVE-2026-58081 — Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the… |
vulnerability |
nvd |
CVE-2026-58081 |
|
2026-08-19 |
| unknown |
CVE-2026-49425 — The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct… |
vulnerability |
nvd |
CVE-2026-49425 |
|
2026-08-19 |
| unknown |
CVE-2026-49424 — The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux… |
vulnerability |
nvd |
CVE-2026-49424 |
|
2026-08-19 |
| medium |
Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer) |
threat-intel |
otx |
05aa847cdfc69a78…, c155a21bec649260… |
clipper, uac bypass, cryptocurrency stealer, byovd, injector, phantomstealer, credential theft, process hollowing, phishing, infostealer |
2026-08-19 |
| high |
CVE-2026-75981 — The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner… |
vulnerability |
nvd |
CVE-2026-75981 |
|
2026-08-19 |
| unknown |
CVE-2026-49423 — When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremen… |
vulnerability |
nvd |
CVE-2026-49423 |
|
2026-08-19 |
| high |
CVE-2026-15780 — The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vu… |
vulnerability |
nvd |
CVE-2026-15780 |
|
2026-08-19 |
| medium |
CVE-2026-15446 — The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data… |
vulnerability |
nvd |
CVE-2026-15446 |
|
2026-08-19 |
| high |
Clop Returns with Custom Implant in Mass-Extortion Campaign |
threat-intel |
otx |
CVE-2021-27101, CVE-2023-34362, CVE-2026-12569 | 78.128.113.10, 216.152.151.204, 185.227.83.236 | 321e1fb01eb3462b…, 71a7b6b8fa5e2176… |
web shell, lemurloot, dewmode, cve-2023-34362, cve-2026-12569, ptc windchill, data exfiltration, manufacturing, credential theft, mass exploitation, extortion, cve-2021-27101, ransomware, phishing |
2026-08-19 |
| medium |
CVE-2026-8810 — On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker… |
vulnerability |
nvd |
CVE-2026-8810 |
|
2026-08-19 |
| unknown |
CVE-2026-49431 — The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an… |
vulnerability |
nvd |
CVE-2026-49431 |
|
2026-08-19 |
| unknown |
CVE-2026-49430 — The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a… |
vulnerability |
nvd |
CVE-2026-49430 |
|
2026-08-19 |
| high |
CVE-2026-49429 — The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to… |
vulnerability |
nvd |
CVE-2026-49429 |
|
2026-08-19 |
| high |
CVE-2026-49428 — Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly fr… |
vulnerability |
nvd |
CVE-2026-49428 |
|
2026-08-19 |
| high |
CVE-2026-49427 — Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) trans… |
vulnerability |
nvd |
CVE-2026-49427 |
|
2026-08-19 |
| unknown |
CVE-2026-49426 — When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of… |
vulnerability |
nvd |
CVE-2026-49426 |
|
2026-08-19 |
| high |
CVE-2026-49422 — The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace… |
vulnerability |
nvd |
CVE-2026-49422 |
|
2026-08-19 |
| unknown |
CVE-2026-49421 — The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH fl… |
vulnerability |
nvd |
CVE-2026-49421 |
|
2026-08-19 |
| high |
CVE-2026-49420 — The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without check… |
vulnerability |
nvd |
CVE-2026-49420 |
rce |
2026-08-19 |
| high |
CVE-2026-19842 — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML respon… |
vulnerability |
nvd |
CVE-2026-19842 |
|
2026-08-19 |
| medium |
CVE-2026-19782 — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJA… |
vulnerability |
nvd |
CVE-2026-19782 |
|
2026-08-19 |
| medium |
CVE-2026-19709 — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer sec… |
vulnerability |
nvd |
CVE-2026-19709 |
|
2026-08-19 |
| medium |
CVE-2026-19417 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to t… |
vulnerability |
nvd |
CVE-2026-19417 |
|
2026-08-19 |
| medium |
CVE-2026-19416 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appoint… |
vulnerability |
nvd |
CVE-2026-19416 |
|
2026-08-19 |
| low |
CVE-2026-19406 — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing… |
vulnerability |
nvd |
CVE-2026-19406 |
|
2026-08-19 |
| high |
CVE-2026-19056 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be… |
vulnerability |
nvd |
CVE-2026-19056 |
|
2026-08-19 |
| high |
CVE-2026-19055 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame… |
vulnerability |
nvd |
CVE-2026-19055 |
|
2026-08-19 |
| critical |
CVE-2026-18937 — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep… |
vulnerability |
nvd |
CVE-2026-18937 |
|
2026-08-19 |
| medium |
CVE-2026-18777 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its… |
vulnerability |
nvd |
CVE-2026-18777, CVE-2026-18779 |
|
2026-08-19 |
| critical |
CVE-2026-18776 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of it… |
vulnerability |
nvd |
CVE-2026-18776, CVE-2026-18778 |
|
2026-08-19 |
| medium |
CVE-2026-18466 — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce,… |
vulnerability |
nvd |
CVE-2026-18466 |
|
2026-08-19 |
| medium |
CVE-2026-18231 — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one o… |
vulnerability |
nvd |
CVE-2026-18231 |
|
2026-08-19 |
| medium |
CVE-2026-18202 — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types… |
vulnerability |
nvd |
CVE-2026-18202 |
|
2026-08-19 |
| critical |
CVE-2026-18051 — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it use… |
vulnerability |
nvd |
CVE-2026-18051 |
|
2026-08-19 |
| critical |
CVE-2026-18031 — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before est… |
vulnerability |
nvd |
CVE-2026-18031 |
|
2026-08-19 |
| high |
CVE-2026-17565 — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied v… |
vulnerability |
nvd |
CVE-2026-17565 |
|
2026-08-19 |
| medium |
CVE-2026-16979 — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform cap… |
vulnerability |
nvd |
CVE-2026-16979 |
|
2026-08-19 |
| high |
CVE-2026-16950 — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet… |
vulnerability |
nvd |
CVE-2026-16950 |
|
2026-08-19 |
| high |
CVE-2026-16617 — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's… |
vulnerability |
nvd |
CVE-2026-16617 |
|
2026-08-19 |
| high |
CVE-2026-16616 — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov… |
vulnerability |
nvd |
CVE-2026-16616 |
|
2026-08-19 |
| high |
CVE-2026-16570 — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t… |
vulnerability |
nvd |
CVE-2026-16570 |
|
2026-08-19 |