CVE-2026-82685
— Confirmation token accepted on any record in AshAuthentication
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take ov…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81829
— Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via un…
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, th…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81637
— Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attack…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81632
— Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use s…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81453
— Dell OpenManage Server Administrator Path Traversal Vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker w…
Remote
|
Path Traversal
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81443
— Dell OpenManage Server Administrator Server-Side Request Forgery Vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit t…
Remote
|
Server-Side Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-81442
— Dell OpenManage Server Administrator Improper Privilege Management Vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this …
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-80355
— Dell OpenManage Server Administrator Cross-Site Request Forgery Vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit …
Remote
|
Cross-Site Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-80218
— Sign-in token minted for one resource accepted by another in AshAuthentication
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource.
A…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-78528
— WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-78295
— WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
Remote
|
Cross-Site Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-78294
— WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-78223
— Token revocation record built from unverified JWT claims in AshAuthentication
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-74017
— WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-74005
— WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnera…
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
Remote
|
Cross-Site Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-74002
— WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-74000
— WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerability
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-73999
— WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) vulnerability
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-71568
— BMCtest exposes Ironic without authentication and TLS during the test
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and si…
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66676
— WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Remote
|
Authorization
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026