CVE-2026-73184
— WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-73183
— WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Remote
|
Injection
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-73182
— WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
Remote
|
Cross-Site Scripting
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-67364
— Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
The form's optional custom-PHP…
Remote
|
Injection
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-67363
— Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4…
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request p…
Remote
|
Authentication
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-66668
— WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Remote
|
Injection
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-66613
— WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Remote
|
Authentication
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-66596
— WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Remote
|
Cross-Site Scripting
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-61986
— WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Remote
|
Cross-Site Scripting
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-32552
— WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerabil…
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Remote
|
Injection
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-19490
— NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Remote
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-19489
— NetScaler ADC and NetScaler Gateway Information Disclosure Vulnerability
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Remote
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.
Remote
|
Cross-Site Scripting
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.
Remote
|
Cross-Site Scripting
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.
openj9
|
Remote
|
Memory Corruption
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-76166
— Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicas…
A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without th…
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-76164
— Authenticated Server-Side Request Forgery in AIL Framework Crawler Allows Access to Inter…
AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit …
Remote
|
Server-Side Request Forgery
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-75900
— Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs siz…
An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh)…
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-75589
— Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signa…
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify.
Each of the three compares the signature carried in the …
|
Cryptography
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
CVE-2026-72889
— Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorit…
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify.
verify resolves the signature method class from the signature_method parameter of the incoming …
|
Authentication
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Aug 19, 2026