CVE-2026-13761 - Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
CVE ID :CVE-2026-13761
Published : Aug. 28, 2026, 1:11 p.m. | 2 hours, 40 minutes ago
Description :Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-13761
Published : Aug. 28, 2026, 1:11 p.m. | 2 hours, 40 minutes ago
Description :Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19412 - Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router
CVE ID :CVE-2026-19412
Published : Aug. 28, 2026, 1:39 p.m. | 2 hours, 12 minutes ago
Description :This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19412
Published : Aug. 28, 2026, 1:39 p.m. | 2 hours, 12 minutes ago
Description :This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15603 - morgan vulnerable to Log Forging via unescaped Unicode line separators
CVE ID :CVE-2026-15603
Published : Aug. 28, 2026, 1:41 p.m. | 2 hours, 10 minutes ago
Description :morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-15603
Published : Aug. 28, 2026, 1:41 p.m. | 2 hours, 10 minutes ago
Description :morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82324 - Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0
CVE ID :CVE-2026-82324
Published : Aug. 28, 2026, 1:47 p.m. | 2 hours, 4 minutes ago
Description :A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82324
Published : Aug. 28, 2026, 1:47 p.m. | 2 hours, 4 minutes ago
Description :A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5800 - Reflected XSS in Dayneks Software's E-Commerce Platform
CVE ID :CVE-2026-5800
Published : Aug. 28, 2026, 1:58 p.m. | 1 hour, 54 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5800
Published : Aug. 28, 2026, 1:58 p.m. | 1 hour, 54 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5953 - Reflected XSS in Ceviz Informatics's Web Design
CVE ID :CVE-2026-5953
Published : Aug. 28, 2026, 2:04 p.m. | 1 hour, 47 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5953
Published : Aug. 28, 2026, 2:04 p.m. | 1 hour, 47 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82327 - Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data
CVE ID :CVE-2026-82327
Published : Aug. 28, 2026, 2:21 p.m. | 1 hour, 31 minutes ago
Description :A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82327
Published : Aug. 28, 2026, 2:21 p.m. | 1 hour, 31 minutes ago
Description :A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82328 - Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
CVE ID :CVE-2026-82328
Published : Aug. 28, 2026, 2:21 p.m. | 1 hour, 31 minutes ago
Description :A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82328
Published : Aug. 28, 2026, 2:21 p.m. | 1 hour, 31 minutes ago
Description :A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82227 - WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability
CVE ID :CVE-2026-82227
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82227
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81284 - WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability
CVE ID :CVE-2026-81284
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81284
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81285 - WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerability
CVE ID :CVE-2026-81285
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81285
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81299 - WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulnerability
CVE ID :CVE-2026-81299
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81299
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81757 - WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-81757
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81757
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81759 - WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-81759
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81759
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81760 - WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81760
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81760
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81761 - WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-81761
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81761
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81767 - WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability
CVE ID :CVE-2026-81767
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81767
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82220 - WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability
CVE ID :CVE-2026-82220
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82220
Published : Aug. 28, 2026, 2:33 p.m. | 1 hour, 18 minutes ago
Description :Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81019 - wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE ID :CVE-2026-81019
Published : Aug. 28, 2026, 2:42 p.m. | 1 hour, 10 minutes ago
Description :wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81019
Published : Aug. 28, 2026, 2:42 p.m. | 1 hour, 10 minutes ago
Description :wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81020 - wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE ID :CVE-2026-81020
Published : Aug. 28, 2026, 2:42 p.m. | 1 hour, 9 minutes ago
Description :wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81020
Published : Aug. 28, 2026, 2:42 p.m. | 1 hour, 9 minutes ago
Description :wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81341 - wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
CVE ID :CVE-2026-81341
Published : Aug. 28, 2026, 2:43 p.m. | 1 hour, 8 minutes ago
Description :wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant across records, so every AES-CCM record within a connection is encrypted under an identical key and nonce pair. Reusing a CCM key and nonce weakens confidentiality (identical keystream across records, so a known record recovers the others) and integrity (authentication tag forgery). Only wolfEngine is affected; wolfProvider is not. AES-GCM under wolfEngine is tracked separately. AES-CCM cipher suites are not enabled by default and must be explicitly selected, which limits exposure. TLS 1.3 and non-TLS use of the cipher are not affected.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81341
Published : Aug. 28, 2026, 2:43 p.m. | 1 hour, 8 minutes ago
Description :wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant across records, so every AES-CCM record within a connection is encrypted under an identical key and nonce pair. Reusing a CCM key and nonce weakens confidentiality (identical keystream across records, so a known record recovers the others) and integrity (authentication tag forgery). Only wolfEngine is affected; wolfProvider is not. AES-GCM under wolfEngine is tracked separately. AES-CCM cipher suites are not enabled by default and must be explicitly selected, which limits exposure. TLS 1.3 and non-TLS use of the cipher are not affected.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...