THREAT OPS › Threat News
Threat Intelligence News
11595 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-20501 (HIGH 8.4) — In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.nvd · 2026-09-07
- [NVD] CVE-2026-20500 (MEDIUM 5.5) — In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.nvd · 2026-09-07
- [NVD] CVE-2026-16876 — An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.nvd · 2026-09-07
- [shinyhunters] Medela.com posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-86238 (MEDIUM 4.3) — A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack mnvd · 2026-09-07
- [NVD] CVE-2026-86237 (MEDIUM 5.3) — A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attanvd · 2026-09-07
- [NVD] CVE-2026-86236 (MEDIUM 6.3) — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploitnvd · 2026-09-07
- Ubuntu Linux Kernel Multiple Vulnerabilitieshkcert · 2026-09-07
- [NVD] CVE-2026-86235 (MEDIUM 6.3) — A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can be initiated remotely. The exploit has beennvd · 2026-09-07
- [NVD] CVE-2026-86234 (MEDIUM 6.3) — A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploitnvd · 2026-09-07
- [NVD] CVE-2026-86233 (MEDIUM 6.3) — A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attanvd · 2026-09-07
- [NVD] CVE-2026-86304 — MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, certnvd · 2026-09-06
- [NVD] CVE-2026-86232 (MEDIUM 6.3) — A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performnvd · 2026-09-06
- [NVD] CVE-2026-86231 (LOW 3.7) — A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attanvd · 2026-09-06
- [NVD] CVE-2026-86228 (MEDIUM 4.3) — A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulationvd · 2026-09-06
- [NVD] CVE-2026-86227 (LOW 3.1) — A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate the attack remotely. The attack is considerenvd · 2026-09-06
- [NVD] CVE-2026-86226 (LOW 3.5) — A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The expnvd · 2026-09-06
- [NVD] CVE-2026-86225 (HIGH 7.3) — A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to nvd · 2026-09-06
- Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)sans_isc · 2026-09-06
- [NVD] CVE-2026-86224 (HIGH 7.3) — A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. Tnvd · 2026-09-06
- Fwd: [mapserver-announce] security release available: MapServer 8.6.6oss_sec · 2026-09-06
- MicroTik Routers Under Attack in New Campaignduo_decipher · 2026-09-06
- [NVD] CVE-2026-86223 (HIGH 7.3) — A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possnvd · 2026-09-06
- [NVD] CVE-2026-86222 (HIGH 7.3) — A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The explonvd · 2026-09-06
- Sponsored: Authentik is rethinking PAM for AI agentsriskybiz_news · 2026-09-06
- [NVD] CVE-2026-86221 (HIGH 7.3) — A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The explnvd · 2026-09-06
- CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file writeoss_sec · 2026-09-06
- CVE-2026-86219: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_steposs_sec · 2026-09-06
- [dragonforce] Homewood Sales posted to leak siteransomware_live · 2026-09-06
- [dragonforce] Norwood Law Firm posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86220 (HIGH 7.3) — A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. nvd · 2026-09-06
- [NVD] CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client retnvd · 2026-09-06
- [NVD] CVE-2026-82209 — When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of convd · 2026-09-06
- [NVD] CVE-2026-82208 — With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected stnvd · 2026-09-06
- [NVD] CVE-2026-80255 — A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests nvd · 2026-09-06
- [NVD] CVE-2026-80230 — When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bnvd · 2026-09-06
- [NVD] CVE-2026-80229 — When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring annvd · 2026-09-06
- [NVD] CVE-2026-19931 — A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.nvd · 2026-09-06
- [NVD] CVE-2026-13608 — A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypassenvd · 2026-09-06
- [DYSPHOR1A] RTAD GOV MM posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When nvd · 2026-09-06
- [NVD] CVE-2026-82750 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When tnvd · 2026-09-06
- [direwolf] eAssist Dental Solutions posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-83534 (MEDIUM 6.4) — PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versionsnvd · 2026-09-06
- [NVD] CVE-2026-19634 (MEDIUM 6.4) — PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious nvd · 2026-09-06
- [NVD] CVE-2026-19633 (HIGH 8.8) — PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanvd · 2026-09-06
- [NVD] CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs thrnvd · 2026-09-06
- [NVD] CVE-2026-86217 (MEDIUM 5.3) — A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remonvd · 2026-09-06
- [Vexy Ransomware] Sancity posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86216 (MEDIUM 4.3) — A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The explonvd · 2026-09-06
- [NVD] CVE-2026-86215 (MEDIUM 4.3) — A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the nvd · 2026-09-06
- [chaos] evergenbio.com posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86259 (HIGH 7.5) — OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitinvd · 2026-09-06
- [NVD] CVE-2026-86258 (MEDIUM 5.9) — nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the roonvd · 2026-09-06
- [NVD] CVE-2026-86214 (HIGH 7.3) — A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publnvd · 2026-09-06
- [NVD] CVE-2026-86213 (HIGH 7.3) — A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be pnvd · 2026-09-06
- [Panzer] KHALED ALFAGIH ENGINEERING CONSULTANCY posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86257 (MEDIUM 5.4) — wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported finvd · 2026-09-06
- [NVD] CVE-2026-86256 (MEDIUM 5.4) — wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET parameter via HttpResponseRedirect() without valnvd · 2026-09-06
- [NVD] CVE-2026-86255 (MEDIUM 6.5) — wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousanvd · 2026-09-06
- [NVD] CVE-2026-86254 (MEDIUM 6.8) — wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff with gym=None to delete, deactivate, or acnvd · 2026-09-06
- [NVD] CVE-2026-86253 (MEDIUM 5.9) — h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. Annvd · 2026-09-06
- [NVD] CVE-2026-86252 (MEDIUM 5.3) — h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multnvd · 2026-09-06
- [NVD] CVE-2026-86251 (MEDIUM 5.9) — h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives resolveDotSegments() because that function onvd · 2026-09-06
- [NVD] CVE-2026-86250 (HIGH 7.5) — h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop thanvd · 2026-09-06
- [NVD] CVE-2026-86242 (HIGH 8.1) — Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefnvd · 2026-09-06
- [NVD] CVE-2026-86212 (MEDIUM 4.3) — A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be usnvd · 2026-09-06
- [NVD] CVE-2026-86205 (MEDIUM 5.4) — h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation nvd · 2026-09-06
- [NVD] CVE-2022-51009 (HIGH 7.5) — PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.nvd · 2026-09-06
- [NVD] CVE-2022-51008 (MEDIUM 5.3) — PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate plnvd · 2026-09-06
- [NVD] CVE-2021-48007 (MEDIUM 6.5) — PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent cnvd · 2026-09-06
- [NVD] CVE-2021-48006 (LOW 3.3) — PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revokenvd · 2026-09-06
- [NVD] CVE-2020-37277 (MEDIUM 6.5) — PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processnvd · 2026-09-06
- [direwolf] myLaurel posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86211 (HIGH 7.3) — A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The expnvd · 2026-09-06
- [Panzer] Edacentrum posted to leak siteransomware_live · 2026-09-06
- [NVD] CVE-2026-86210 (HIGH 7.3) — A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launnvd · 2026-09-06
- [NVD] CVE-2026-86209 (HIGH 7.3) — A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made availabnvd · 2026-09-06
- [NVD] CVE-2026-86208 (HIGH 7.3) — A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been rnvd · 2026-09-06
- [NVD] CVE-2026-80439 (MEDIUM 4.8) — The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticanvd · 2026-09-06
- [NVD] CVE-2026-80437 (MEDIUM 4.8) — The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the sitnvd · 2026-09-06
- [NVD] CVE-2026-19862 (MEDIUM 4.8) — The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hinvd · 2026-09-06
- [NVD] CVE-2026-19859 (MEDIUM 6.5) — The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that contennvd · 2026-09-06
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authenticationthehackernews · 2026-09-06
- [NVD] CVE-2026-86183 (MEDIUM 5.3) — A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypanvd · 2026-09-06
- [NVD] CVE-2026-86182 (MEDIUM 4.3) — A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgenvd · 2026-09-06
- [NVD] CVE-2026-86181 (LOW 3.5) — A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The atnvd · 2026-09-06
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Minerthehackernews · 2026-09-06
- [NVD] CVE-2026-86180 (HIGH 7.3) — A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated nvd · 2026-09-06
- [NVD] CVE-2026-86179 (MEDIUM 5.3) — A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attanvd · 2026-09-06
- [NVD] CVE-2026-86172 (MEDIUM 6.3) — A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public anvd · 2026-09-06
- [NVD] CVE-2026-86171 (MEDIUM 6.3) — A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed punvd · 2026-09-06
- [NVD] CVE-2026-85038 (MEDIUM 5.3) — The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assignvd · 2026-09-06
- [NVD] CVE-2026-84219 (HIGH 7.5) — The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an admininvd · 2026-09-06
- [NVD] CVE-2026-84028 (MEDIUM 6.8) — The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.nvd · 2026-09-06
- [NVD] CVE-2026-75793 (MEDIUM 6.5) — The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.nvd · 2026-09-06
- [NVD] CVE-2026-18480 (HIGH 8.8) — The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, andnvd · 2026-09-06
- [NVD] CVE-2026-13159 (MEDIUM 4.3) — The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the snvd · 2026-09-06
- [NVD] CVE-2026-86170 (MEDIUM 6.3) — A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made avnvd · 2026-09-06
- [NVD] CVE-2026-86168 (HIGH 7.3) — A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been rnvd · 2026-09-06