๐จ CVE-2026-23934
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
๐@cveNotify
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
๐@cveNotify
๐จ CVE-2026-23935
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
๐@cveNotify
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
๐@cveNotify
๐จ CVE-2026-23937
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
๐@cveNotify
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
๐@cveNotify
๐จ CVE-2026-23938
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
๐@cveNotify
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
๐@cveNotify
๐จ CVE-2026-59781
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by the application, resulting in DLL sideloading. The installer has been hardened to detect potentially unsafe installation directories and now requires explicit user confirmation before proceeding with installation in such locations. This reduces the risk of accidental installation into directories with inappropriate permissions while preserving compatibility with existing deployment scenarios.
๐@cveNotify
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by the application, resulting in DLL sideloading. The installer has been hardened to detect potentially unsafe installation directories and now requires explicit user confirmation before proceeding with installation in such locations. This reduces the risk of accidental installation into directories with inappropriate permissions while preserving compatibility with existing deployment scenarios.
๐@cveNotify
๐จ CVE-2026-75783
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
๐@cveNotify
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
๐@cveNotify
GitHub
CVE/team15_20260702/01_wlc100p-netifd/poc/poc-netifd-overflow.py at main ยท meishigana/CVE
for_my_cve. Contribute to meishigana/CVE development by creating an account on GitHub.
๐จ CVE-2026-17084
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
๐@cveNotify
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
๐@cveNotify
GitHub
stringprep and IDNA 2003 incorrectly handles some characters ยท Issue #155292 ยท python/cpython
Linked PRs gh-155293 gh-156017
๐จ CVE-2026-24301
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-28192
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
๐@cveNotify
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Piotnet Addons For Elementor Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28567
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
๐@cveNotify
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress WP Sort Order Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28568
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Quill Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28569
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress SSL Zen Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28570
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
๐@cveNotify
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
๐@cveNotify
Patchstack
Local File Inclusion in WordPress Vavo Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28571
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
๐@cveNotify
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress FormyChat Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32333
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Mayosis Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32444
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
๐@cveNotify
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
๐@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress Cwicly Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32463
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
๐@cveNotify
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Sync Post With Other Site Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32464
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
๐@cveNotify
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
๐@cveNotify
Patchstack
Local File Inclusion in WordPress Theme Test Drive Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32465
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
๐@cveNotify
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Essential Real Estate Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32466
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
๐@cveNotify
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Gravity Forms Bookings premium Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32467
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
๐@cveNotify
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress [Aotuman] Grab WeChat Articles Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.