CVE-2019-10086 · 2026-08-25 · auto
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev…
CVE-2018-1258 · 2026-08-25 · auto
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met…
CVE-2026-74982 · 2026-08-25 · auto
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74981 · 2026-08-25 · auto
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74978 · 2026-08-25 · auto
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74977 · 2026-08-25 · auto
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-75918 · 2026-08-25 · auto
phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extra…
CVE-2026-72700 · 2026-08-25 · auto
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controll…
CVE-2025-46252 · 2026-08-24 · auto
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection.
This issue affects Message Filter for Contact For…
CVE-2026-28153 · 2026-08-24 · auto
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
CVE-2026-78209 · 2026-08-24 · auto
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute w…
CVE-2026-78208 · 2026-08-24 · auto
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the No…
CVE-2026-78206 · 2026-08-24 · auto
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand …
CVE-2026-16149 · 2026-08-23 · auto
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled b…
CVE-2026-0551 · 2026-08-23 · auto
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable…
CVE-2026-2996 · 2026-08-22 · auto
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart…
CVE-2026-76793 · 2026-08-23 · auto
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthentic…
CVE-2026-76789 · 2026-08-23 · auto
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allow…
CVE-2026-19221 · 2026-08-23 · auto
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code acr…
CVE-2026-18052 · 2026-08-23 · auto
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who…
CVE-2026-19883 · 2026-08-22 · auto
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in …
CVE-2026-74960 · 2026-08-24 · auto
Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74957 · 2026-08-24 · auto
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-3985 · 2026-08-21 · auto
The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insuffi…
CVE-2026-8497 · 2026-08-21 · auto
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify …
CVE-2026-38970 · 2026-08-21 · auto
pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, including arrays, via ParseObjectContext() and p…
CVE-2026-72818 · 2026-08-21 · auto
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* i…
CVE-2026-76350 · 2026-08-21 · auto
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action wo…
CVE-2026-74953 · 2026-08-21 · auto
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74952 · 2026-08-21 · auto
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
CVE-2026-74949 · 2026-08-24 · auto
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153…
CVE-2026-54616 · 2026-08-20 · auto
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/A…
CVE-2026-74966 · 2026-08-25 · auto
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-66594 · 2026-08-20 · auto
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-14948 · 2026-08-20 · auto
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable e…
CVE-2026-75963 · 2026-08-20 · auto
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attack…
CVE-2026-15049 · 2026-08-20 · auto
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access…
CVE-2021-42296 · 2026-08-19 · auto
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-40442 · 2026-08-19 · auto
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27058 · 2026-08-19 · auto
Microsoft Office ClickToRun Remote Code Execution Vulnerability
CVE-2021-27057 · 2026-08-19 · auto
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-27056 · 2026-08-19 · auto
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2021-27055 · 2026-08-19 · auto
Microsoft Visio Security Feature Bypass Vulnerability
CVE-2021-27054 · 2026-08-19 · auto
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27053 · 2026-08-19 · auto
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24108 · 2026-08-19 · auto
Microsoft Office Remote Code Execution Vulnerability
CVE-2023-29550 · 2026-08-19 · auto
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary cod…
CVE-2023-29541 · 2026-08-19 · auto
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Oth…
CVE-2023-29539 · 2026-08-19 · auto
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially trick…
CVE-2023-29536 · 2026-08-19 · auto
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability aff…