| medium |
CVE-2026-45734 — MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consiste… |
vulnerability |
nvd |
CVE-2026-45734 |
ransomware |
2026-08-18 |
| medium |
CVE-2026-45129 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module doe… |
vulnerability |
nvd |
CVE-2026-45129 |
|
2026-08-18 |
| low |
CVE-2026-45128 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does… |
vulnerability |
nvd |
CVE-2026-45128 |
|
2026-08-18 |
| low |
CVE-2026-45127 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not vali… |
vulnerability |
nvd |
CVE-2026-45127 |
|
2026-08-18 |
| low |
CVE-2026-45126 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module… |
vulnerability |
nvd |
CVE-2026-45126 |
|
2026-08-18 |
| medium |
CVE-2026-45125 — MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not san… |
vulnerability |
nvd |
CVE-2026-45125 |
|
2026-08-18 |
| medium |
CVE-2026-45124 — MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not chec… |
vulnerability |
nvd |
CVE-2026-45124 |
|
2026-08-18 |
| medium |
CVE-2026-45123 — MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not c… |
vulnerability |
nvd |
CVE-2026-45123 |
|
2026-08-18 |
| medium |
CVE-2026-45122 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate… |
vulnerability |
nvd |
CVE-2026-45122 |
|
2026-08-18 |
| medium |
CVE-2026-45121 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check per… |
vulnerability |
nvd |
CVE-2026-45121 |
|
2026-08-18 |
| medium |
CVE-2026-45120 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify pr… |
vulnerability |
nvd |
CVE-2026-45120 |
|
2026-08-18 |
| medium |
CVE-2026-45119 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module d… |
vulnerability |
nvd |
CVE-2026-45119 |
|
2026-08-18 |
| critical |
CVE-2026-45118 — MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a… |
vulnerability |
nvd |
CVE-2026-45118 |
|
2026-08-18 |
| critical |
CVE-2026-45117 — MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not… |
vulnerability |
nvd |
CVE-2026-45117 |
rce |
2026-08-18 |
| high |
CVE-2026-45116 — MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly… |
vulnerability |
nvd |
CVE-2026-45116 |
|
2026-08-18 |
| high |
CVE-2026-45115 — MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sa… |
vulnerability |
nvd |
CVE-2026-45115 |
|
2026-08-18 |
| high |
CVE-2026-19501 — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize sprea… |
vulnerability |
nvd |
CVE-2026-19501 |
|
2026-08-18 |
| high |
CVE-2026-19500 — The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adeq… |
vulnerability |
nvd |
CVE-2026-19500 |
|
2026-08-18 |
| unknown |
CVE-2026-15806 — The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWit… |
vulnerability |
nvd |
CVE-2026-15806 |
|
2026-08-18 |
| critical |
CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() fu… |
vulnerability |
nvd |
CVE-2026-12564 |
|
2026-08-18 |
| medium |
Signed Overwolf Binary Sideloads ValleyRAT Malware in India |
threat-intel |
otx |
103.240.196.115 | 2d2a251a88632f01…, 315bda377beafb74… |
india taxation phishing, upx packing, valleyrat, astral-pe, overwolf abuse, reflective loading, process hollowing, dll sideloading, phishing, botnet |
2026-08-18 |
| high |
Fraudulent Employment Operations |
threat-intel |
otx |
104.253.147.147, 104.253.51.76, 104.253.72.75, 104.253.134.123, 218.24.120.118, 104.253.1.79, 104.253.103.238, 104.253.111.106, 104.253.112.86, 104.253.121.146, 104.253.17.141, 104.253.19.244, 104.253.199.214, 104.253.251.19, 104.253.34.67, 104.253.47.239, 104.253.56.226, 104.253.90.150 |
insider threat, identity fraud, north korean it workers, remote work deception, fraudulent employment, purpledelta, chatgpt abuse, ai-generated personas |
2026-08-18 |
| high |
CVE-2026-75898 — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "In… |
vulnerability |
nvd |
CVE-2026-75898 |
|
2026-08-18 |
| unknown |
CVE-2026-75890 — Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that a… |
vulnerability |
nvd |
CVE-2026-75890 |
|
2026-08-18 |
| unknown |
CVE-2026-75872 — HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticat… |
vulnerability |
nvd |
CVE-2026-75872 |
|
2026-08-18 |
| critical |
CVE-2026-75784 — A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the functio… |
vulnerability |
nvd |
CVE-2026-75784 |
|
2026-08-18 |
| medium |
CVE-2026-75032 — A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems respons… |
vulnerability |
nvd |
CVE-2026-75032 |
|
2026-08-18 |
| critical |
CVE-2026-74015 — Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
vulnerability |
nvd |
CVE-2026-74015 |
|
2026-08-18 |
| high |
CVE-2026-74012 — Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue aff… |
vulnerability |
nvd |
CVE-2026-74012 |
|
2026-08-18 |
| medium |
CVE-2026-74009 — Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versio… |
vulnerability |
nvd |
CVE-2026-74009 |
|
2026-08-18 |
| medium |
CVE-2026-74008 — Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22… |
vulnerability |
nvd |
CVE-2026-74008 |
|
2026-08-18 |
| medium |
CVE-2026-74007 — Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery… |
vulnerability |
nvd |
CVE-2026-74007 |
|
2026-08-18 |
| medium |
CVE-2026-74006 — Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. |
vulnerability |
nvd |
CVE-2026-74006 |
|
2026-08-18 |
| medium |
CVE-2026-74004 — Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <… |
vulnerability |
nvd |
CVE-2026-74004 |
|
2026-08-18 |
| medium |
CVE-2026-74003 — Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. |
vulnerability |
nvd |
CVE-2026-74003 |
|
2026-08-18 |
| high |
CVE-2026-73997 — Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
vulnerability |
nvd |
CVE-2026-73997 |
|
2026-08-18 |
| critical |
CVE-2026-73996 — Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
vulnerability |
nvd |
CVE-2026-73996 |
|
2026-08-18 |
| medium |
CVE-2026-73995 — Subscriber Broken Authentication in User Registration <= 5.2.6 versions. |
vulnerability |
nvd |
CVE-2026-73995 |
|
2026-08-18 |
| high |
CVE-2026-73994 — Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
vulnerability |
nvd |
CVE-2026-73994 |
|
2026-08-18 |
| medium |
CVE-2026-73426 — Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix… |
vulnerability |
nvd |
CVE-2026-73426 |
|
2026-08-18 |
| medium |
CVE-2026-73404 — Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. |
vulnerability |
nvd |
CVE-2026-73404 |
|
2026-08-18 |
| high |
CVE-2026-73400 — Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
vulnerability |
nvd |
CVE-2026-73400 |
|
2026-08-18 |
| medium |
CVE-2026-73399 — Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
vulnerability |
nvd |
CVE-2026-73399 |
|
2026-08-18 |
| medium |
CVE-2026-73398 — Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
vulnerability |
nvd |
CVE-2026-73398 |
|
2026-08-18 |
| critical |
CVE-2026-73397 — Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
vulnerability |
nvd |
CVE-2026-73397 |
|
2026-08-18 |
| high |
CVE-2026-73396 — Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
vulnerability |
nvd |
CVE-2026-73396 |
|
2026-08-18 |
| medium |
CVE-2026-73395 — Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking Sy… |
vulnerability |
nvd |
CVE-2026-73395 |
|
2026-08-18 |
| high |
CVE-2026-73393 — Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. |
vulnerability |
nvd |
CVE-2026-73393 |
|
2026-08-18 |
| critical |
CVE-2026-73392 — Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. |
vulnerability |
nvd |
CVE-2026-73392 |
|
2026-08-18 |
| medium |
CVE-2026-73383 — Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. |
vulnerability |
nvd |
CVE-2026-73383 |
|
2026-08-18 |