CVE-2026-19697 - GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
CVE ID :CVE-2026-19697
Published : Aug. 20, 2026, 6:17 a.m. | 33 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19697
Published : Aug. 20, 2026, 6:17 a.m. | 33 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19699 - GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
CVE ID :CVE-2026-19699
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19699
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73542 - Seiko Epson Printers and Scanners Improper Certificate Validation Vulnerability
CVE ID :CVE-2026-73542
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-73542
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74992 - Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload
CVE ID :CVE-2026-74992
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-74992
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75860 - JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update
CVE ID :CVE-2026-75860
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-75860
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75963 - Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property
CVE ID :CVE-2026-75963
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-75963
Published : Aug. 20, 2026, 6:17 a.m. | 32 minutes ago
Description :The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71368 - F-RevoCRM Cross-Site Scripting Vulnerability
CVE ID :CVE-2026-71368
Published : Aug. 20, 2026, 6:28 a.m. | 21 minutes ago
Description :F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-71368
Published : Aug. 20, 2026, 6:28 a.m. | 21 minutes ago
Description :F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14602 - Weak File Name Generation in vsDesk
CVE ID :CVE-2025-14602
Published : Aug. 20, 2026, 7:16 a.m. | 3 hours, 33 minutes ago
Description :The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14602
Published : Aug. 20, 2026, 7:16 a.m. | 3 hours, 33 minutes ago
Description :The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14163 - Octopus Server Sensitive Variable Information Disclosure
CVE ID :CVE-2026-14163
Published : Aug. 20, 2026, 7:16 a.m. | 3 hours, 33 minutes ago
Description :In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14163
Published : Aug. 20, 2026, 7:16 a.m. | 3 hours, 33 minutes ago
Description :In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14601 - vsDesk Task Scheduler OS Command Injection
CVE ID :CVE-2025-14601
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14601
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75948 - Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12
CVE ID :CVE-2026-75948
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-75948
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76564 - Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
CVE ID :CVE-2026-76564
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-76564
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76565 - Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
CVE ID :CVE-2026-76565
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-76565
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76569 - Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
CVE ID :CVE-2026-76569
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-76569
Published : Aug. 20, 2026, 8:16 a.m. | 2 hours, 33 minutes ago
Description :Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14946 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious configuration file.
CVE ID :CVE-2026-14946
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14946
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14947 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
CVE ID :CVE-2026-14947
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14947
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14948 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive Information into Log File via error log archives
CVE ID :CVE-2026-14948
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14948
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14949 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control
CVE ID :CVE-2026-14949
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14949
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14950 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic
CVE ID :CVE-2026-14950
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14950
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14951 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Cross-Site Request Forgery due to missing CSFR protection headers
CVE ID :CVE-2026-14951
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14951
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14952 - Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication
CVE ID :CVE-2026-14952
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14952
Published : Aug. 20, 2026, 9:16 a.m. | 1 hour, 33 minutes ago
Description :An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...