CVE-2026-100739
— mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manip…
Remote
|
Injection
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94408
— Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94400
— Uncontrolled Resource Consumption in Kibana Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
kibana
|
Remote
|
Denial of Service
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94399
— Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94398
— Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94397
— Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94396
— Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-82300
— Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-82294
— Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-78582
— Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Syn…
kibana
|
Remote
|
Authorization
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-72668
— Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escal…
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged o…
kibana
|
Remote
|
Authorization
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-72662
— Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclo…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by AC…
kibana
|
Remote
|
Authorization
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-82901
— Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Sig…
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions …
Remote
|
Authentication
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-85984
— miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authe…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5…
Remote
|
Authentication
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-77203
— Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shor…
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving …
Remote
|
Authorization
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-97163
— Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin exte…
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Remote
|
Authentication
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-97162
— Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0…
Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Remote
|
Injection
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-97161
— Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin …
Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Remote
|
Path Traversal
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-97160
— Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plug…
Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Remote
|
Injection
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
CVE-2026-94132
— Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action…
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_a…
Remote
|
Injection
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Sep 26, 2026