🚨 CVE-2026-17497
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
🎖@cveNotify
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
🎖@cveNotify
GitHub
GitHub - codexu/note-gen: Capture first. Organize later. A local-first Markdown app that turns scattered records into clear notes…
Capture first. Organize later. A local-first Markdown app that turns scattered records into clear notes with AI. - codexu/note-gen
🚨 CVE-2026-57989
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-15928
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
🎖@cveNotify
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
🎖@cveNotify
🚨 CVE-2025-15662
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.
🎖@cveNotify
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.
🎖@cveNotify
WPScan
Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
See details on Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery CVE 2025-15662. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12255
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
🎖@cveNotify
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
🎖@cveNotify
WPScan
MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
See details on MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration CVE 2026-12255. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12394
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
🎖@cveNotify
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
🎖@cveNotify
WPScan
MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
See details on MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator CVE 2026-12394. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13152
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.
🎖@cveNotify
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.
🎖@cveNotify
WPScan
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
See details on Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation CVE 2026-13152. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13714
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
🎖@cveNotify
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
🎖@cveNotify
WPScan
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
See details on Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution CVE 2026-13714. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13726
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
WPScan
Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
See details on Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode CVE 2026-13726. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14189
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
🎖@cveNotify
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
🎖@cveNotify
WPScan
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
See details on WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields CVE 2026-14189. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14190
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.
🎖@cveNotify
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.
🎖@cveNotify
WPScan
Sina Extension for Elementor < 3.10.2 - Reflected XSS
See details on Sina Extension for Elementor < 3.10.2 - Reflected XSS CVE 2026-14190. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12495
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
🎖@cveNotify
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
🎖@cveNotify
www.incibe.es
Stack-Based Buffer Overflow in the Mercusys MB115-4G
INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting the Mercusys MB115-
🚨 CVE-2026-14856
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.
🎖@cveNotify
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.
🎖@cveNotify
www.incibe.es
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
INCIBE has coordinated the publication of a medium-severity vulnerability affecting TastyIgniter Media
🚨 CVE-2026-57916
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
This issue was fixed in version 9.4.3.90.
🎖@cveNotify
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
This issue was fixed in version 9.4.3.90.
🎖@cveNotify
cert.pl
Podatności w oprogramowaniu proCertum SmartSign
W oprogramowaniu proCertum SmartSign wykryto 2 podatności różnego typu (CVE-2026-57916 oraz CVE-2026-57917)
🚨 CVE-2026-57917
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”.
This issue was fixed in version 9.4.3.90.
🎖@cveNotify
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”.
This issue was fixed in version 9.4.3.90.
🎖@cveNotify
cert.pl
Podatności w oprogramowaniu proCertum SmartSign
W oprogramowaniu proCertum SmartSign wykryto 2 podatności różnego typu (CVE-2026-57916 oraz CVE-2026-57917)
🚨 CVE-2026-12989
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.
🎖@cveNotify
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.
🎖@cveNotify
www.incibe.es
Multiple vulnerabilities in Ghost Robotics' Vision 60
INCIBE has coordinated the disclosure of three high-severity vulnerabilities affecting Ghost Robotics'
🚨 CVE-2026-12990
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
🎖@cveNotify
An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
🎖@cveNotify
www.incibe.es
Multiple vulnerabilities in Ghost Robotics' Vision 60
INCIBE has coordinated the disclosure of three high-severity vulnerabilities affecting Ghost Robotics'
🚨 CVE-2026-12991
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
🎖@cveNotify
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
🎖@cveNotify
www.incibe.es
Multiple vulnerabilities in Ghost Robotics' Vision 60
INCIBE has coordinated the disclosure of three high-severity vulnerabilities affecting Ghost Robotics'
🚨 CVE-2026-56538
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
🎖@cveNotify
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
🎖@cveNotify
Hcl-Software
Security Bulletin: HCL Connections Security Update for Information Disclosure Vulnerabilities (CVE-2026-56537, CVE-2026-56538)…
HCL Connections is vulnerable to information disclosure, see details below for description and remediation
🚨 CVE-2026-59686
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
🎖@cveNotify
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
🎖@cveNotify
Progress
LoadMaster Critical Security Bulletin – July 2026 – (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690)…
The Progress Kemp LoadMaster team recently confirmed a series of high-severity vulnerabilities in Progress Kemp LoadMaster, Progress ECS Connection Manager and Progress Connection Manager for ObjectScale GA v7.2.63.2 and older, Progress Kemp LoadMaster LTSF…
🚨 CVE-2026-59687
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
🎖@cveNotify
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
🎖@cveNotify
Progress
LoadMaster Critical Security Bulletin – July 2026 – (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690)…
The Progress Kemp LoadMaster team recently confirmed a series of high-severity vulnerabilities in Progress Kemp LoadMaster, Progress ECS Connection Manager and Progress Connection Manager for ObjectScale GA v7.2.63.2 and older, Progress Kemp LoadMaster LTSF…