CVE-2026-81794
— WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vul…
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81793
— WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81791
— WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
Remote
|
Cross-Site Scripting
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81789
— WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary Fi…
Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81788
— WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81787
— WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81786
— WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Contr…
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81785
— WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81784
— WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
Remote
|
Injection
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81783
— WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulner…
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81782
— WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81275
— WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-78536
— WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Contr…
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-66674
— WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-66632
— WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vulnerability
Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
Remote
|
Injection
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-46387
— Suricata http2: decompression bomb can cause denial of service in Suricata
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could gr…
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could derefer…
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-15461
— Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gn…
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88009
— Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassin…
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empt…
|
Misconfiguration
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88921
— MISP: Unescaped HTML Injection in PDF Report Element Rendering
MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTM…
Remote
|
Injection
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026