CVE Notify
19.5K subscribers
4 photos
229K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-15787
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.

🎖@cveNotify
🚨 CVE-2026-2406
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client.

This issue affects Online Registration and Workflow Management System: through 12022026.

🎖@cveNotify
🚨 CVE-2026-63264
The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

🎖@cveNotify
🚨 CVE-2026-56183
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-14551
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility UpdaterAction.exe with SYSTEM privileges, which parses the instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination (e.g., overwriting a service binary). This leads to full system compromise as the service automatically restarts the overwritten binary with SYSTEM privileges.

🎖@cveNotify
🚨 CVE-2026-56182
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-58533
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62826
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-56184
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-56187
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-56189
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-56194
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-58534
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-16473
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

🎖@cveNotify
🚨 CVE-2026-56175
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-56181
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

🎖@cveNotify
🚨 CVE-2026-56188
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2023-3390
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c.

Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue.

We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97

🎖@cveNotify