THREAT OPS › Threat News
Threat Intelligence News
11576 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-90576 (LOW 3.3) — A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local nvd · 2026-09-13
- [NVD] CVE-2020-15875 (MEDIUM 5.0) — An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, ednvd · 2026-09-13
- [NVD] CVE-2026-90575 (LOW 3.7) — A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotenvd · 2026-09-13
- [NVD] CVE-2026-90574 (MEDIUM 6.3) — A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The exnvd · 2026-09-13
- [NVD] CVE-2026-90573 (LOW 3.3) — A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The explonvd · 2026-09-13
- [NVD] CVE-2026-90572 (MEDIUM 4.7) — A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed nvd · 2026-09-13
- [NVD] CVE-2026-90571 (MEDIUM 4.3) — A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scrnvd · 2026-09-13
- [NVD] CVE-2026-90570 (LOW 2.4) — A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leadnvd · 2026-09-13
- [NVD] CVE-2026-90569 (LOW 2.4) — A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scriptingnvd · 2026-09-13
- [NVD] CVE-2026-90568 (LOW 3.5) — A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross sitenvd · 2026-09-13
- [qilin] Gilco Scaffolding posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90567 (LOW 3.5) — A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross sitnvd · 2026-09-13
- [NVD] CVE-2026-90566 (HIGH 7.3) — A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the nvd · 2026-09-13
- [NVD] CVE-2026-90565 (MEDIUM 5.3) — A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possinvd · 2026-09-13
- [NVD] CVE-2026-90564 (LOW 3.5) — A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scrinvd · 2026-09-13
- [NVD] CVE-2026-90563 (LOW 3.5) — A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.nvd · 2026-09-13
- [NVD] CVE-2026-90529 (LOW 3.5) — A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument cannvd · 2026-09-13
- [NVD] CVE-2026-90528 (LOW 3.5) — A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cronvd · 2026-09-13
- [NVD] CVE-2026-90527 (MEDIUM 4.3) — A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attacnvd · 2026-09-13
- Re: AI slops from Eveoss_sec · 2026-09-13
- August 2026 Dark Web Breach Incident Trend Reportahnlab · 2026-09-13
- August 2026 Dark Web Threat Actor Trend Reportahnlab · 2026-09-13
- August 2026 Dark Web Issue Trend Reportahnlab · 2026-09-13
- Re: AI slops from Eveoss_sec · 2026-09-13
- CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Pageoss_sec · 2026-09-13
- CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keysoss_sec · 2026-09-13
- CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPCoss_sec · 2026-09-13
- CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Originsoss_sec · 2026-09-13
- CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logvieweross_sec · 2026-09-13
- CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decodeross_sec · 2026-09-13
- CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logsoss_sec · 2026-09-13
- CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UIoss_sec · 2026-09-13
- CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overridesoss_sec · 2026-09-13
- CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.usersoss_sec · 2026-09-13
- CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenantoss_sec · 2026-09-13
- CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcheross_sec · 2026-09-13
- CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keysoss_sec · 2026-09-13
- CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Nameoss_sec · 2026-09-13
- [NVD] CVE-2026-90526 (HIGH 7.3) — A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possiblenvd · 2026-09-13
- [NVD] CVE-2026-90525 (MEDIUM 6.3) — A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit hanvd · 2026-09-13
- [NVD] CVE-2026-90524 (HIGH 7.3) — A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack manvd · 2026-09-13
- [NVD] CVE-2026-90523 (HIGH 7.3) — A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Sucnvd · 2026-09-13
- GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efioss_sec · 2026-09-13
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-13
- [emperador] Navitrans posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90783 (HIGH 7.8) — MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing nvd · 2026-09-13
- [NVD] CVE-2026-90782 (MEDIUM 5.3) — S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocatinvd · 2026-09-13
- [NVD] CVE-2026-90781 (MEDIUM 4.4) — alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through savednvd · 2026-09-13
- [NVD] CVE-2026-90522 (HIGH 7.3) — A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The nvd · 2026-09-13
- [NVD] CVE-2026-90521 (MEDIUM 6.3) — A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorinvd · 2026-09-13
- [NVD] CVE-2026-90520 (MEDIUM 6.3) — A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to impronvd · 2026-09-13
- [NVD] CVE-2026-90519 (MEDIUM 6.3) — A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. nvd · 2026-09-13
- [krybit] www.kashkha.com posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90780 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflonvd · 2026-09-13
- [NVD] CVE-2026-90779 (HIGH 7.5) — SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client procnvd · 2026-09-13
- [NVD] CVE-2026-90778 (HIGH 7.5) — SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static bufnvd · 2026-09-13
- [NVD] CVE-2026-90777 (HIGH 8.8) — ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through thenvd · 2026-09-13
- [NVD] CVE-2026-90776 (HIGH 7.5) — Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and blonvd · 2026-09-13
- [NVD] CVE-2026-90775 (MEDIUM 6.5) — PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, cnvd · 2026-09-13
- [NVD] CVE-2026-90518 (MEDIUM 6.3) — A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been nvd · 2026-09-13
- [NVD] CVE-2026-90517 (MEDIUM 5.3) — A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is pubnvd · 2026-09-13
- [NVD] CVE-2026-90516 (HIGH 7.3) — A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotelnvd · 2026-09-13
- [NVD] CVE-2026-90515 (HIGH 7.3) — A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launchenvd · 2026-09-13
- [NVD] CVE-2026-90774 (HIGH 7.5) — rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured uploanvd · 2026-09-13
- [NVD] CVE-2026-90773 (LOW 3.2) — procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to othernvd · 2026-09-13
- [NVD] CVE-2026-90772 (HIGH 7.6) — Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadanvd · 2026-09-13
- [NVD] CVE-2026-90771 (LOW 3.7) — joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstreamnvd · 2026-09-13
- [NVD] CVE-2026-90770 (HIGH 8.8) — Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monvd · 2026-09-13
- [NVD] CVE-2026-90769 (HIGH 7.7) — Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bnvd · 2026-09-13
- [NVD] CVE-2026-90768 (HIGH 8.1) — CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view nvd · 2026-09-13
- [NVD] CVE-2026-90767 (MEDIUM 6.5) — Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthoriznvd · 2026-09-13
- [NVD] CVE-2026-90562 (HIGH 8.1) — LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admnvd · 2026-09-13
- [NVD] CVE-2026-90561 (HIGH 8.7) — Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields thnvd · 2026-09-13
- [NVD] CVE-2026-90514 (HIGH 7.3) — A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The expnvd · 2026-09-13
- [NVD] CVE-2026-90513 (MEDIUM 6.5) — A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmnvd · 2026-09-13
- [NVD] CVE-2026-90511 (MEDIUM 6.3) — A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column rnvd · 2026-09-13
- [NVD] CVE-2026-90510 (HIGH 8.3) — A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/imnvd · 2026-09-13
- [qilin] CARIDRO VAL DE LOIRE posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90509 (HIGH 7.3) — A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploinvd · 2026-09-13
- [NVD] CVE-2026-90508 (LOW 3.4) — A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing nvd · 2026-09-13
- [NVD] CVE-2026-90507 (MEDIUM 6.3) — A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to impnvd · 2026-09-13
- [NVD] CVE-2026-90506 (MEDIUM 5.0) — A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is nvd · 2026-09-13
- [NVD] CVE-2026-90505 (MEDIUM 5.0) — A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The nvd · 2026-09-13
- [NVD] CVE-2026-90504 (HIGH 7.3) — A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploinvd · 2026-09-13
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Datathehackernews · 2026-09-13
- [AuditTeam] Paid Victim F9CF4B639CAC1B18 posted to leak siteransomware_live · 2026-09-13
- [AuditTeam] Paid Victim FDC699DE3A112669 posted to leak siteransomware_live · 2026-09-13
- [AuditTeam] vi***in posted to leak siteransomware_live · 2026-09-13
- [Barracuda] i2i-systems posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90503 (LOW 2.3) — A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched nvd · 2026-09-13
- [NVD] CVE-2026-90502 (LOW 3.5) — A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attnvd · 2026-09-13
- [shinyhunters] Kimberly-Clark posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-90501 (MEDIUM 6.3) — A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. Thnvd · 2026-09-13
- [NVD] CVE-2026-90500 (MEDIUM 6.3) — A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried onvd · 2026-09-13
- [NVD] CVE-2026-89080 (HIGH 7.5) — The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user'snvd · 2026-09-13
- [NVD] CVE-2026-88995 (MEDIUM 5.3) — The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and connvd · 2026-09-13
- [NVD] CVE-2026-88912 (MEDIUM 4.2) — The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level acconvd · 2026-09-13
- [NVD] CVE-2026-88764 (MEDIUM 5.4) — The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, nvd · 2026-09-13
- [NVD] CVE-2026-86407 (LOW 3.7) — The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve nvd · 2026-09-13
- [NVD] CVE-2026-86406 (HIGH 7.5) — The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted thenvd · 2026-09-13