🚨 CVE-2026-14682
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
🎖@cveNotify
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.
🎖@cveNotify
GitHub
Grow ASN.1 definite-length objects incrementally via Streams.readLenB… · bcgit/bc-java@37094e5
…ytesFully() rather than allocating the full declared length up front, so a short crafted header over a raw stream cannot drive a heap-sized allocation before any data is read (CWE-789); DefiniteLe...
🚨 CVE-2026-18584
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
🎖@cveNotify
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
🎖@cveNotify
GitHub
CVE-issues/4.0.0/Unauthenticated access to eSIM LPA API via nginx proxy bypass.md at main · gl-inet/CVE-issues
Contribute to gl-inet/CVE-issues development by creating an account on GitHub.
🚨 CVE-2026-6694
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.
🎖@cveNotify
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.
🎖@cveNotify
🚨 CVE-2026-12965
The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.
🎖@cveNotify
The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.
🎖@cveNotify
WPScan
Super Store Finder <= 7.10 - Unauthenticated SQL Injection via ssf_tracking
See details on Super Store Finder <= 7.10 - Unauthenticated SQL Injection via ssf_tracking CVE 2026-12965. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15254
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.
🎖@cveNotify
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records, including names, email addresses, phone numbers and notes, across the whole site.
🎖@cveNotify
WPScan
Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
See details on Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode CVE 2026-15254. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16289
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
🎖@cveNotify
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
🎖@cveNotify
WPScan
ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
See details on ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group CVE 2026-16289. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16297
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
🎖@cveNotify
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
🎖@cveNotify
WPScan
Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import
See details on Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import CVE 2026-16297. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16300
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
WPScan
Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
See details on Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset CVE 2026-16300. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16532
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
🎖@cveNotify
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
🎖@cveNotify
WPScan
Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
See details on Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form CVE 2026-16532. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16534
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
🎖@cveNotify
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
🎖@cveNotify
WPScan
Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
See details on Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import CVE 2026-16534. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16563
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
🎖@cveNotify
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
🎖@cveNotify
WPScan
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
See details on Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint CVE 2026-16563. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16572
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
🎖@cveNotify
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
🎖@cveNotify
WPScan
LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
See details on LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie CVE 2026-16572. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-4793
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
🎖@cveNotify
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
🎖@cveNotify
Synology
Synology_SA_26_12 | Synology Inc.
Synology Product Security Advisory
🚨 CVE-2026-18590
A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
🎖@cveNotify
A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
🎖@cveNotify
🚨 CVE-2026-28147
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
🎖@cveNotify
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-60011
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
🎖@cveNotify
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
🎖@cveNotify
corporate.jp.sharp
弊社複合機における複数のセキュリティ脆弱性について|製品セキュリティアドバイザリ|製品セキュリティ:シャープ株式会社
弊社複合機における複数のセキュリティ脆弱性に関するお知らせです。
🚨 CVE-2026-62416
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
🎖@cveNotify
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.
🎖@cveNotify
corporate.jp.sharp
弊社複合機関連アプリケーションにおけるセキュリティ脆弱性について|製品セキュリティアドバイザリ|製品セキュリティ:シャープ株式会社
弊社複合機関連アプリケーションにおけるセキュリティ脆弱性に関するお知らせです。
🚨 CVE-2026-63545
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
🎖@cveNotify
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
🎖@cveNotify
corporate.jp.sharp
弊社複合機における複数のセキュリティ脆弱性について|製品セキュリティアドバイザリ|製品セキュリティ:シャープ株式会社
弊社複合機における複数のセキュリティ脆弱性に関するお知らせです。
🚨 CVE-2026-63563
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication.
Products intended for the Japanese market are not affected.
🎖@cveNotify
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication.
Products intended for the Japanese market are not affected.
🎖@cveNotify
corporate.jp.sharp
弊社複合機における複数のセキュリティ脆弱性について|製品セキュリティアドバイザリ|製品セキュリティ:シャープ株式会社
弊社複合機における複数のセキュリティ脆弱性に関するお知らせです。
🚨 CVE-2026-18574
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
🎖@cveNotify
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
🎖@cveNotify
Checkpoint
sk185222 - CVE-2026-18574 - Management Authentication Bypass
Applies to: Multi-Domain Security Management Server, Security Management Server
🚨 CVE-2026-56608
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
🎖@cveNotify
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL iControl (CVE-2026-56608 and CVE-2026-56609) - Customer Support
HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).