CVE-2026-32559 - WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability
CVE ID :CVE-2026-32559
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32559
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32560 - WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion vulnerability
CVE ID :CVE-2026-32560
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32560
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32561 - WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability
CVE ID :CVE-2026-32561
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32561
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-32563 - WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability
CVE ID :CVE-2026-32563
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32563
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45404 - OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
CVE ID :CVE-2026-45404
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45404
Published : Aug. 24, 2026, 10:16 p.m. | 36 minutes ago
Description :OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68516 - OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow
CVE ID :CVE-2026-68516
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-68516
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77337 - CakePHP: Potential Authentication bypass with CookieAuthenticator
CVE ID :CVE-2026-77337
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-77337
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77384 - libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion
CVE ID :CVE-2026-77384
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-77384
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78259 - WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability
CVE ID :CVE-2026-78259
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78259
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78262 - WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability
CVE ID :CVE-2026-78262
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78262
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78263 - WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-78263
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78263
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78264 - WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-78264
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78264
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78265 - WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability
CVE ID :CVE-2026-78265
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78265
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78266 - WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability
CVE ID :CVE-2026-78266
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78266
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78267 - WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability
CVE ID :CVE-2026-78267
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78267
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78268 - WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-78268
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78268
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78282 - WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-78282
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78282
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78284 - WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability
CVE ID :CVE-2026-78284
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78284
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78434 - Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication
CVE ID :CVE-2026-78434
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78434
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78435 - Faveo Helpdesk Logo SettingsController.php unlink path traversal
CVE ID :CVE-2026-78435
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78435
Published : Aug. 24, 2026, 10:17 p.m. | 35 minutes ago
Description :A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53532 - OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)
CVE ID :CVE-2026-53532
Published : Aug. 24, 2026, 10:24 p.m. | 28 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-53532
Published : Aug. 24, 2026, 10:24 p.m. | 28 minutes ago
Description :OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...