CVE-2026-81625
— Stack buffer overflow in Greenbone OS and openvas-scanner
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromi…
Remote
|
Memory Corruption
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81581
— User input in WibuKey is used (without proper sanitization) to compute the address of a p…
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually resu…
|
Memory Corruption
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81579
— An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileg…
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabli…
|
Memory Corruption
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force…
Remote
|
Authentication
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data l…
Remote
|
Denial of Service
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to re…
Remote
|
Injection
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81573
— Improper Access Control in Local-Only Configuration Commands
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network …
Remote
|
Misconfiguration
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81572
— Local Privilege Escalation in CodeMeter Runtime on Windows
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic link…
|
Path Traversal
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81279
— WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken Access Contro…
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Remote
|
Authorization
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81277
— WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerability
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Remote
|
Injection
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81276
— WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Remote
|
Authorization
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81274
— WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
ditty
|
Remote
|
Authorization
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81273
— WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerabi…
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Remote
|
Cross-Site Request Forgery
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81272
— WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Remote
|
Authorization
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-81271
— WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Remote
|
Cross-Site Request Forgery
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-80433
— WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure vulnerabili…
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Remote
|
Information Disclosure
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-78293
— WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Remote
|
Cross-Site Scripting
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-78292
— WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-78289
— WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Remote
|
Cross-Site Scripting
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
CVE-2026-78288
— WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Remote
|
Injection
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Aug 27, 2026