| medium |
CVE-2026-16058 — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on… |
vulnerability |
nvd |
CVE-2026-16058 |
|
2026-08-19 |
| medium |
CVE-2026-15253 — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment tit… |
vulnerability |
nvd |
CVE-2026-15253 |
|
2026-08-19 |
| high |
CVE-2026-14861 — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request… |
vulnerability |
nvd |
CVE-2026-14861 |
|
2026-08-19 |
| low |
CVE-2026-14825 — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object owners… |
vulnerability |
nvd |
CVE-2026-14825, CVE-2026-14826 |
|
2026-08-19 |
| high |
CVE-2026-14334 — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s… |
vulnerability |
nvd |
CVE-2026-14334 |
|
2026-08-19 |
| medium |
CVE-2026-14287 — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an u… |
vulnerability |
nvd |
CVE-2026-14287 |
|
2026-08-19 |
| medium |
CVE-2026-14196 — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a… |
vulnerability |
nvd |
CVE-2026-14196 |
|
2026-08-19 |
| medium |
CVE-2026-13175 — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule record… |
vulnerability |
nvd |
CVE-2026-13175 |
|
2026-08-19 |
| high |
CVE-2026-13174 — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting u… |
vulnerability |
nvd |
CVE-2026-13174 |
|
2026-08-19 |
| low |
CVE-2026-13173 — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit oth… |
vulnerability |
nvd |
CVE-2026-13173 |
|
2026-08-19 |
| high |
CVE-2026-13169 — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allow… |
vulnerability |
nvd |
CVE-2026-13169 |
|
2026-08-19 |
| high |
CVE-2026-12983 — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in… |
vulnerability |
nvd |
CVE-2026-12983 |
|
2026-08-19 |
| high |
CVE-2026-11565 — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in sever… |
vulnerability |
nvd |
CVE-2026-11565 |
|
2026-08-19 |
| unknown |
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure |
news |
general-news |
|
|
2026-08-19 |
| critical |
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data |
news |
general-news |
|
ransomware |
2026-08-19 |
| unknown |
CVE-2026-70408 — An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-… |
vulnerability |
nvd |
CVE-2026-70408 |
|
2026-08-19 |
| unknown |
CVE-2026-66358 — A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an a… |
vulnerability |
nvd |
CVE-2026-66358 |
|
2026-08-19 |
| high |
CVE-2026-49419 — When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference… |
vulnerability |
nvd |
CVE-2026-49419 |
|
2026-08-19 |
| high |
CVE-2026-49418 — When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages i… |
vulnerability |
nvd |
CVE-2026-49418 |
|
2026-08-19 |
| high |
CVE-2026-49415 — During execve(2) of a SUID binary, the new virtual address space is installed before the process cre… |
vulnerability |
nvd |
CVE-2026-49415 |
|
2026-08-19 |
| high |
CVE-2026-19942 — The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback pl… |
vulnerability |
nvd |
CVE-2026-19942 |
rce |
2026-08-19 |
| high |
CVE-2026-76050 — A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an… |
vulnerability |
nvd |
CVE-2026-76050 |
|
2026-08-19 |
| high |
CVE-2026-76049 — A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affect… |
vulnerability |
nvd |
CVE-2026-76049 |
|
2026-08-19 |
| high |
CVE-2026-76048 — A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element… |
vulnerability |
nvd |
CVE-2026-76048 |
|
2026-08-19 |
| low |
CVE-2026-76014 — A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of t… |
vulnerability |
nvd |
CVE-2026-76014 |
|
2026-08-19 |
| critical |
CVE-2026-76008 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the… |
vulnerability |
nvd |
CVE-2026-76008 |
|
2026-08-19 |
| critical |
CVE-2026-76004 — A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected b… |
vulnerability |
nvd |
CVE-2026-76004 |
|
2026-08-19 |
| critical |
CVE-2026-76003 — A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strc… |
vulnerability |
nvd |
CVE-2026-76003 |
|
2026-08-19 |
| high |
CVE-2026-75987 — A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStr… |
vulnerability |
nvd |
CVE-2026-75987 |
|
2026-08-19 |
| high |
CVE-2026-75986 — A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element i… |
vulnerability |
nvd |
CVE-2026-75986 |
|
2026-08-19 |
| high |
CVE-2026-75985 — A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of t… |
vulnerability |
nvd |
CVE-2026-75985 |
|
2026-08-19 |
| medium |
CVE-2026-15421 — The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable… |
vulnerability |
nvd |
CVE-2026-15421 |
|
2026-08-19 |
| unknown |
CVE-2026-11751 — A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS… |
vulnerability |
nvd |
CVE-2026-11751 |
|
2026-08-19 |
| high |
CVE-2026-75984 — A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of th… |
vulnerability |
nvd |
CVE-2026-75984 |
|
2026-08-19 |
| medium |
CVE-2026-75979 — A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function… |
vulnerability |
nvd |
CVE-2026-75979 |
|
2026-08-19 |
| unknown |
China-Linked Hacker Shows AI Capabilities in APAC Attack |
news |
general-news |
|
|
2026-08-19 |
| medium |
CVE-2026-75978 — A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affe… |
vulnerability |
nvd |
CVE-2026-75978 |
|
2026-08-19 |
| critical |
CVE-2026-75976 — A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of… |
vulnerability |
nvd |
CVE-2026-75976 |
|
2026-08-19 |
| medium |
CVE-2025-11729 — The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable… |
vulnerability |
nvd |
CVE-2025-11729 |
|
2026-08-19 |
| critical |
CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-64849, CVE-2026-69146, CVE-2026-69148 |
|
2026-08-19 |
| medium |
CVE-2026-66589 — Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configure… |
vulnerability |
nvd |
CVE-2026-66589 |
|
2026-08-18 |
| high |
CVE-2026-66602 — Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar all… |
vulnerability |
nvd |
CVE-2026-66602 |
|
2026-08-18 |
| medium |
CVE-2026-62377 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF se… |
vulnerability |
nvd |
CVE-2026-62377 |
|
2026-08-18 |
| unknown |
CVE-2026-62292 — libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted unco… |
vulnerability |
nvd |
CVE-2026-62292 |
|
2026-08-18 |
| medium |
CVE-2026-62291 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image s… |
vulnerability |
nvd |
CVE-2026-62291 |
|
2026-08-18 |
| medium |
CVE-2026-62289 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or… |
vulnerability |
nvd |
CVE-2026-62289 |
|
2026-08-18 |
| medium |
CVE-2026-53959 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any a… |
vulnerability |
nvd |
CVE-2026-53959 |
phishing |
2026-08-18 |
| high |
CVE-2026-53958 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au… |
vulnerability |
nvd |
CVE-2026-53958 |
|
2026-08-18 |
| high |
CVE-2026-52876 — Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v… |
vulnerability |
nvd |
CVE-2026-52876, CVE-2026-52877 |
ransomware |
2026-08-18 |
| medium |
CVE-2026-52873 — Streambert is a cross-platform Electron Desktop App to stream and download video content. From versi… |
vulnerability |
nvd |
CVE-2026-52873 |
|
2026-08-18 |