π¨ CVE-2026-65490
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
π@cveNotify
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Create by Mediavine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65496
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
π@cveNotify
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Complianz Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65499
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
π@cveNotify
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress PeproDev Ultimate Invoice Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65503
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ultimate Store Kit Elementor Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65514
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Appointment Hour Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65519
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
π@cveNotify
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Photo Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65524
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
π@cveNotify
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Avada Custom Branding Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65527
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress LIQUID SPEECH BALLOON Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65530
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
π@cveNotify
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress TemplateSpare Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65533
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Smart SEO Tool Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65539
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Kwayy HTML Sitemap Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-15037
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
π@cveNotify
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
π@cveNotify
π¨ CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65907
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65908
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-14257
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
π@cveNotify
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
π@cveNotify
GitHub
GitHub - juliangruber/brace-expansion: Brace expansion, as known from sh/bash, in JavaScript
Brace expansion, as known from sh/bash, in JavaScript - juliangruber/brace-expansion
π¨ CVE-2026-16733
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - bahmutov/find-cypress-specs: Find Cypress spec files using the config settings
Find Cypress spec files using the config settings. Contribute to bahmutov/find-cypress-specs development by creating an account on GitHub.
π¨ CVE-2026-16735
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - release-it/conventional-changelog: Conventional changelog plugin for release-it
Conventional changelog plugin for release-it. Contribute to release-it/conventional-changelog development by creating an account on GitHub.
π¨ CVE-2026-8287
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation.
This issue affects Online Pre-Accounting Software: through 17072026.
π@cveNotify
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation.
This issue affects Online Pre-Accounting Software: through 17072026.
π@cveNotify
siberguvenlik.gov.tr
T.C. Siber GΓΌvenlik BaΕkanlΔ±ΔΔ±
TΓΌrkiye Cumhuriyeti CumhurbaΕkanlΔ±ΔΔ± Siber GΓΌvenlik BaΕkanlΔ±ΔΔ± resmi web sitesi.
π¨ CVE-2026-43820
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
π@cveNotify
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
π@cveNotify
GitHub
Accessing bytes of non-string SAN can lead to out-of-bounds memory read
### Summary
`NIOSSLCertificate._subjectAlternativeNames` provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an `ASN1_STRING`, but ...
`NIOSSLCertificate._subjectAlternativeNames` provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an `ASN1_STRING`, but ...