CVE-2026-97181 - ezGlobal|GPM LIGHT - Sensitive Data Exposure
CVE ID :CVE-2026-97181
Published : Sept. 24, 2026, 8:17 a.m. | 3 hours, 3 minutes ago
Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97181
Published : Sept. 24, 2026, 8:17 a.m. | 3 hours, 3 minutes ago
Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77193 - eesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter
CVE ID :CVE-2026-77193
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-77193
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78308 - Authentication Bypass in DIAEnergie
CVE ID :CVE-2026-78308
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78308
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78309 - SQL Injection in DIAEnergie
CVE ID :CVE-2026-78309
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78309
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78310 - Authorization Bypass Through User-Controlled Key in DIAEnergie
CVE ID :CVE-2026-78310
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78310
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78311 - SQL Injection in DIAEnergie
CVE ID :CVE-2026-78311
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78311
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78312 - Path Traversal in DIAEnergie
CVE ID :CVE-2026-78312
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78312
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78313 - Improper Access Control in DIAEnergie
CVE ID :CVE-2026-78313
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78313
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85682 - YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route
CVE ID :CVE-2026-85682
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-85682
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97185 - Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
CVE ID :CVE-2026-97185
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97185
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12227 - Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter
CVE ID :CVE-2026-12227
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12227
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15731 - WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
CVE ID :CVE-2026-15731
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-15731
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18335 - Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter
CVE ID :CVE-2026-18335
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18335
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4637 - Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor
CVE ID :CVE-2026-4637
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated, remote attacker can craft a URL containing an HTML/JavaScript payload in the path (e.g. https:////welcome.htm) and, once a victim with an active PRTG session opens the crafted link, execute arbitrary JavaScript in the security context of the PRTG web interface. Because the PRTG session cookie is not protected with the HttpOnly attribute, successful exploitation allows the attacker to read and exfiltrate the victim's session cookie, potentially leading to session hijacking.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4637
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated, remote attacker can craft a URL containing an HTML/JavaScript payload in the path (e.g. https:////welcome.htm) and, once a victim with an active PRTG session opens the crafted link, execute arbitrary JavaScript in the security context of the PRTG web interface. Because the PRTG session cookie is not protected with the HttpOnly attribute, successful exploitation allows the attacker to read and exfiltrate the victim's session cookie, potentially leading to session hijacking.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57590 - Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations
CVE ID :CVE-2026-57590
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-57590
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92905 - Denial of Service Vulnerability
CVE ID :CVE-2026-92905
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92905
Published : Sept. 24, 2026, 10:17 a.m. | 1 hour, 2 minutes ago
Description :ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97179 - O2OA Cipher Connection CipherConnectionAction.java list information disclosure
CVE ID :CVE-2026-97179
Published : Sept. 24, 2026, 10:30 a.m. | 49 minutes ago
Description :A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97179
Published : Sept. 24, 2026, 10:30 a.m. | 49 minutes ago
Description :A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79680 - Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module
CVE ID :CVE-2026-79680
Published : Sept. 24, 2026, 10:56 a.m. | 23 minutes ago
Description :Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.
Severity: 4.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-79680
Published : Sept. 24, 2026, 10:56 a.m. | 23 minutes ago
Description :Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.
Severity: 4.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4638 - Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor
CVE ID :CVE-2026-4638
Published : Sept. 24, 2026, 10:57 a.m. | 22 minutes ago
Description :PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter. Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4638
Published : Sept. 24, 2026, 10:57 a.m. | 22 minutes ago
Description :PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter. Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77874 - IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
CVE ID :CVE-2026-77874
Published : Sept. 24, 2026, 2:22 p.m. | 58 minutes ago
Description :IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-77874
Published : Sept. 24, 2026, 2:22 p.m. | 58 minutes ago
Description :IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81539 - DataStage on Cloud Pak for Data has several vulnerabilities
CVE ID :CVE-2026-81539
Published : Sept. 24, 2026, 2:23 p.m. | 57 minutes ago
Description :IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81539
Published : Sept. 24, 2026, 2:23 p.m. | 57 minutes ago
Description :IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...