๐จ CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Dynamic Pricing With Discount Rules for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Events Made Easy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65433
Subscriber Broken Access Control in RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
๐@cveNotify
Subscriber Broken Access Control in RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65434
Subscriber Sensitive Data Exposure in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Subscriber Sensitive Data Exposure in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress ะฎKassa ะดะปั WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65435
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Thrive Leads Version Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65561
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WordPress Social Login and Register Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65562
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress BetterDocs Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65563
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
๐@cveNotify
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Orbit Fox by ThemeIsle Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66427
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
๐@cveNotify
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress WP Google Review Slider Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66428
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress WP Google Review Slider Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66433
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Location Weather Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66445
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Open User Map Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66448
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Gallery PhotoBlocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2025-50455
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.
๐@cveNotify
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.
๐@cveNotify
GitHub
security-advisories/CVE-2025-50455/advisory.md at main ยท threatlance-org/security-advisories
Contribute to threatlance-org/security-advisories development by creating an account on GitHub.
๐จ CVE-2026-16812
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited.
๐@cveNotify
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited.
๐@cveNotify
Arista Networks
Security Advisory 0144 - Arista
July 27, 2026 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality,
๐จ CVE-2026-17529
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.
๐@cveNotify
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.
๐@cveNotify
GitHub
GitHub - AstrBotDevs/AstrBot: AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins andโฆ
AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins and AI feature, and can be your openclaw alternative. โจ - AstrBotDevs/AstrBot
๐จ CVE-2026-17530
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.
๐@cveNotify
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.
๐@cveNotify
GitHub
GitHub - AstrBotDevs/AstrBot: AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins andโฆ
AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins and AI feature, and can be your openclaw alternative. โจ - AstrBotDevs/AstrBot
๐จ CVE-2026-17572
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
๐@cveNotify
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
๐@cveNotify
GitHub
SOHM list message count exceeds list_max ยท Issue #6501 ยท HDFGroup/hdf5
When a shared object header message index is stored as a list, both H5SM__cache_list_verify_chksum() and H5SM__cache_list_deserialize() take the num_messages count straight from the on-disk index h...
๐จ CVE-2026-17574
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
๐@cveNotify
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
๐@cveNotify
GitHub
Validate VL datatype type during decode and check file pointer in H5Tโฆ ยท HDFGroup/hdf5@3fa6ed6
โฆ_set_loc (#6395)
H5O__dtype_decode_helper() reads vlen.type from the file without
validation. With corrupted HDF5 files (e.g. from fuzzing), this field
can have an invalid value that is neither H...
H5O__dtype_decode_helper() reads vlen.type from the file without
validation. With corrupted HDF5 files (e.g. from fuzzing), this field
can have an invalid value that is neither H...