CVE-2026-16534 - Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
CVE ID :CVE-2026-16534
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16534
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16539 - SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
CVE ID :CVE-2026-16539
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16539
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16563 - Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
CVE ID :CVE-2026-16563
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16563
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16564 - Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
CVE ID :CVE-2026-16564
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16564
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16565 - Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
CVE ID :CVE-2026-16565
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16565
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16572 - LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
CVE ID :CVE-2026-16572
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-16572
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18587 - Wavlink WL-NU516U1 Config Import os command injection
CVE ID :CVE-2026-18587
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18587
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18588 - Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow
CVE ID :CVE-2026-18588
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18588
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18589 - Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow
CVE ID :CVE-2026-18589
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18589
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 10.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4793 - Synology Assistant Incorrect Default Permissions Vulnerability
CVE ID :CVE-2026-4793
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4793
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9593 - iDTM FDI Unauthorized Debug Interface Enablement
CVE ID :CVE-2026-9593
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-9593
Published : Aug. 3, 2026, 7:16 a.m. | 43 minutes ago
Description :A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21548 - NR Modem Improper Input Validation Vulnerability
CVE ID :CVE-2026-21548
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21548
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21549 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21549
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21549
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21550 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21550
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21550
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21551 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21551
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21551
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21552 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21552
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21552
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21553 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21553
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21553
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21554 - Modem Improper Input Validation Vulnerability
CVE ID :CVE-2026-21554
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21554
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21555 - Modem Improper Input Validation Denial of Service
CVE ID :CVE-2026-21555
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21555
Published : Aug. 3, 2026, 7:18 a.m. | 42 minutes ago
Description :In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18592 - osCommerce Email Template Configuration EmailController.php EmailController sql injection
CVE ID :CVE-2026-18592
Published : Aug. 3, 2026, 7:30 a.m. | 30 minutes ago
Description :A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18592
Published : Aug. 3, 2026, 7:30 a.m. | 30 minutes ago
Description :A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18593 - vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox
CVE ID :CVE-2026-18593
Published : Aug. 3, 2026, 7:45 a.m. | 15 minutes ago
Description :A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18593
Published : Aug. 3, 2026, 7:45 a.m. | 15 minutes ago
Description :A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...