π¨ CVE-2026-19384
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
π@cveNotify
GitHub
sourcecodester Simple Doctor's Appointment System using PHP/MySQL with Source Code V1.0 /doctors/admin/ajax.php?action=set_appointmentβ¦
sourcecodester Simple Doctor's Appointment System using PHP/MySQL with Source Code V1.0 /doctors/admin/ajax.php?action=set_appointment SQL injection NAME OF AFFECTED PRODUCT(S) Simple Doctor...
π¨ CVE-2026-19387
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
π@cveNotify
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.
π@cveNotify
Redhat
CVE-2026-19387 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-19389
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
π@cveNotify
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
π@cveNotify
Redhat
CVE-2026-19389 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-72522
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
π@cveNotify
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2053153. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-12570
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.
π@cveNotify
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.
π@cveNotify
GitHub
Fix: reject HDF5 shape-bomb datasets in the main load_model/load_weig⦠· keras-team/keras@4933ea4
β¦hts path (#22975)
* Reject HDF5 datasets that declare far more data than is stored
safe_get_h5_dataset materialized an h5py dataset sized to its declared
shape without checking how much data is ...
* Reject HDF5 datasets that declare far more data than is stored
safe_get_h5_dataset materialized an h5py dataset sized to its declared
shape without checking how much data is ...
π¨ CVE-2026-12971
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
π@cveNotify
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
π@cveNotify
WPScan
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
See details on LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature CVE 2026-12971. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13133
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
π@cveNotify
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
π@cveNotify
π¨ CVE-2026-13170
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
π@cveNotify
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
π@cveNotify
WPScan
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
See details on Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting CVE 2026-13170. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13600
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
π@cveNotify
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
π@cveNotify
WPScan
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
See details on AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron CVE 2026-13600. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13701
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.
π@cveNotify
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.
π@cveNotify
WPScan
Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
See details on Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting CVE 2026-13701. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14206
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
π@cveNotify
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
π@cveNotify
WPScan
HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
See details on HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure CVE 2026-14206. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14211
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
π@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
π@cveNotify
WPScan
Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR
See details on Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR CVE 2026-14211. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14237
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
π@cveNotify
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
π@cveNotify
WPScan
Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
See details on Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation CVE 2026-14237. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14238
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.
π@cveNotify
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.
π@cveNotify
WPScan
Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report
See details on Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report CVE 2026-14238. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14293
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
π@cveNotify
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
π@cveNotify
WPScan
Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor
See details on Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor CVE 2026-14293. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14860
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
π@cveNotify
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
π@cveNotify
WPScan
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
See details on Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery CVE 2026-14860. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14941
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
π@cveNotify
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
π@cveNotify
WPScan
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
See details on Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions CVE 2026-14941. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15047
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
π@cveNotify
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
π@cveNotify
WPScan
s2Member < 260805 - Contributor+ Stored XSS via Shortcode
See details on s2Member < 260805 - Contributor+ Stored XSS via Shortcode CVE 2026-15047. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15229
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
π@cveNotify
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
π@cveNotify
WPScan
Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation
See details on Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation CVE 2026-15229. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15237
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
π@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
π@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
See details on Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint CVE 2026-15237. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15238
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
π@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
π@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
See details on Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR CVE 2026-15238. View the latest Plugin Vulnerabilities on WPScan.