Recent
Open Redirect in MISP Installer-Generated Apache Configuration
Published 2026-07-28 by CIRCL
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 by apache
Anchore Enterprise Privilege Escalation via User Management API
Published 2026-07-28 by VulnCheck
Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
Published 2026-07-28 by TR-CERT
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Published 2026-07-28 by Mattermost
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick
Published 2026-07-28 by CIRCL
Apache Axis2/Java: deserialization of untrusted Data
Published 2026-07-28 by apache
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Published 2026-07-28 by apache
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Published 2026-07-28 by apache
Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests
Published 2026-07-28 by CIRCL
Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulation and Denial of Service
Published 2026-07-28 by CIRCL
Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References
Published 2026-07-28 by CIRCL
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
Published 2026-07-28 by CIRCL
Stored DOM-Based Cross-Site Scripting in Node Modal Headers
Published 2026-07-28 by CIRCL
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
Published 2026-07-28 by VulDB
Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash
Published 2026-07-28 by redhat
DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
Published 2026-07-28 by CIRCL
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
Published 2026-07-28 by Joomla
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
Published 2026-07-28 by Wordfence
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Published 2026-07-28 by Wordfence
Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1
Published 2026-07-28 by Joomla
PoD: Don't try to reclaim special pages
Published 2026-07-28 by XEN
correct buffer checks for DM_OP hypercalls
Published 2026-07-28 by XEN
evtchn: Race between FIFO expand and reset
Published 2026-07-28 by XEN
Viridian STIMER division by zero
Published 2026-07-28 by XEN
x86: Out-of-bounds read in vRTC emulation
Published 2026-07-28 by XEN
vNUMA domain cleanup may race other operations
Published 2026-07-28 by XEN
grant-table: version change racing with other operations
Published 2026-07-28 by XEN
grant-table: version change racing with other operations
Published 2026-07-28 by XEN
grant-table: type confusion in grant-copy
Published 2026-07-28 by XEN
sysctl and platform-op locks open to abuse
Published 2026-07-28 by XEN
sysctl and platform-op locks open to abuse
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
vIRQ event channel binding may break Xenstore
Published 2026-07-28 by XEN
x86 shadow paging is deprecated
Published 2026-07-28 by XEN
Improper Authentication in Universal Sotware's UKBS
Published 2026-07-28 by TR-CERT
Zip Bomb in Lookyloo Capture Upload Allows Denial of Service
Published 2026-07-28 by CIRCL
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
Published 2026-07-28 by redhat
Hard-coded admin credentials in Quick.Cart
Published 2026-07-28 by CERT-PL
Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
Published 2026-07-28 by INCIBE
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action
Published 2026-07-28 by Wordfence
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action
Published 2026-07-28 by Wordfence
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
Published 2026-07-28 by Wordfence
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter
Published 2026-07-28 by Wordfence
WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action
Published 2026-07-28 by Wordfence
WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action
Published 2026-07-28 by Wordfence
Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
Published 2026-07-28 by Wordfence
Published 2026-07-28 by SamsungMobile
Path Traversal in Quick.CMS
Published 2026-07-28 by CERT-PL
Local File Inclusion in Quick.CMS
Published 2026-07-28 by CERT-PL
Denial of Service in Quick.CMS
Published 2026-07-28 by CERT-PL
Missing authorization check in event quick setup view
Published 2026-07-28 by rami.io
Insufficient validation of payment status in pretix-girosolution
Published 2026-07-28 by rami.io
Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
Published 2026-07-28 by Joomla
Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers
Published 2026-07-28 by redhat
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
Published 2026-07-28 by EEF
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS
Published 2026-07-28 by EEF
Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2026-07-28 by sap
Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection
Published 2026-07-28 by Wordfence
Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute
Published 2026-07-28 by Wordfence
Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint
Published 2026-07-28 by Wordfence
PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter
Published 2026-07-28 by Wordfence
SQL injection via unauthenticated GetGridData endpoint
Published 2026-07-28 by CERTVDE
CVE-2026-11841
Published 2026-07-28 by SICK AG
ads-tec Industrial IT: Post-login open redirect in the web interface
Published 2026-07-28 by CERTVDE
ads-tec Industrial IT: Account lockout via non-atomic user creation
Published 2026-07-28 by CERTVDE
ads-tec Industrial IT: Vertical privilege escalation via configuration table write
Published 2026-07-28 by CERTVDE
ads-tec Industrial IT: Privilege escalation during configuration import
Published 2026-07-28 by CERTVDE
MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server
Published 2026-07-28 by alibaba
Published 2026-07-28 by jpcert
Published 2026-07-28 by jpcert
Published 2026-07-28 by jpcert
Premium Packages <= 6.2.0 - Unauthenticated SQL Injection
Published 2026-07-28 by Wordfence
TrueBooker <= 1.2.2 - Unauthenticated SQL Injection
Published 2026-07-28 by Wordfence
Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
Published 2026-07-28 by Wordfence
Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection
Published 2026-07-28 by Wordfence
Reflected XSS in theWP's News Theme V8
Published 2026-07-28 by TR-CERT
Bypass of application rate-limiting mechanism
Published 2026-07-28 by CSA
ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)
Published 2026-07-28 by bcorg
WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
Published 2026-07-28 by Wordfence
Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x
Published 2026-07-28 by 3DS
GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute
Published 2026-07-28 by Wordfence
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings
Published 2026-07-28 by Wordfence
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
Published 2026-07-28 by Wordfence
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter
Published 2026-07-28 by Wordfence
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
Published 2026-07-28 by Wordfence
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
Published 2026-07-28 by WPScan
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
Published 2026-07-28 by WPScan
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
Published 2026-07-28 by WPScan
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
Published 2026-07-28 by WPScan
Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
Published 2026-07-28 by WPScan
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
Published 2026-07-28 by WPScan
Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter
Published 2026-07-28 by Wordfence
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
Published 2026-07-28 by Wordfence
Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function
Published 2026-07-28 by Wordfence
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries
Published 2026-07-28 by Wordfence
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
Published 2026-07-28 by Wordfence
Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
Published 2026-07-28 by Wordfence
Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
Published 2026-07-28 by Wordfence
Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter
Published 2026-07-28 by Wordfence
PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter
Published 2026-07-28 by Wordfence
Published 2026-07-28 by snyk
Published 2026-07-28 by snyk
Published 2026-07-28 by mitre
Published 2026-07-28 by mitre
Published 2026-07-28 by mitre
Published 2026-07-28 by mitre
Published 2026-07-28 by mitre
Published 2026-07-28 by mitre
WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability
Published 2026-07-27 by Patchstack
WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability
Published 2026-07-27 by Patchstack
WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulnerability
Published 2026-07-27 by Patchstack
WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF) vulnerability
Published 2026-07-27 by Patchstack
WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
Published 2026-07-27 by Patchstack
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Published 2026-07-27 by GitHub_M
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Published 2026-07-27 by GitHub_M
React Router: Open redirect can lead to XSS
Published 2026-07-27 by GitHub_M
Load more ↓