🚨 CVE-2026-34501
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
🎖@cveNotify
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
🎖@cveNotify
🚨 CVE-2026-34502
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client
This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
🎖@cveNotify
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client
This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
🎖@cveNotify
🚨 CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
🎖@cveNotify
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
🎖@cveNotify
GitHub
GitHub - openchamber/openchamber: Agentic Development Environment based on OpenCode AI agent
Agentic Development Environment based on OpenCode AI agent - openchamber/openchamber
🚨 CVE-2026-53976
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.
🎖@cveNotify
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.
🎖@cveNotify
GitHub
GitHub - openchamber/openchamber: Agentic Development Environment based on OpenCode AI agent
Agentic Development Environment based on OpenCode AI agent - openchamber/openchamber
🚨 CVE-2026-54489
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
🎖@cveNotify
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
🎖@cveNotify
🚨 CVE-2026-61959
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Business Directory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress EmbedPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61963
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Media LIbrary Assistant Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61982
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
🎖@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress BOX NOW Delivery Croatia Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65508
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65509
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress wpDataTables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65513
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65517
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Easy PayPal Buy Now Button Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65523
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
🎖@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Formidable Forms Signature Online Contract Automation Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65541
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Staff Training Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65542
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.