π¨ CVE-2026-61407
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
π@cveNotify
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
π@cveNotify
π¨ CVE-2026-63632
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.
π@cveNotify
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.
π@cveNotify
GitHub
fix: add input rank checks in Gemm version converter adapters (#7880) Β· onnx/onnx@e9c74f5
### Motivation and Context
The Gemm 6β7 and 7β6 version converter adapters accessed `A_shape[0]`,
`A_shape[1]`, `B_shape[0]`, and `B_shape[1]` without first verifying
that
inputs A and B have at l...
The Gemm 6β7 and 7β6 version converter adapters accessed `A_shape[0]`,
`A_shape[1]`, `B_shape[0]`, and `B_shape[1]` without first verifying
that
inputs A and B have at l...
π¨ CVE-2026-63639
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
π@cveNotify
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
π@cveNotify
GitHub
fix: Reject corrupt stream RDB with shared NACK across consumers (#4073) Β· valkey-io/valkey@06bc776
When loading a stream consumer group from RDB, the loader assigns each
NACK's consumer pointer without checking if it was already set. A
corrupt RDB payload can list the same message ID und...
NACK's consumer pointer without checking if it was already set. A
corrupt RDB payload can list the same message ID und...
π¨ CVE-2026-66046
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
π@cveNotify
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
π@cveNotify
GitHub
[CVE-2026-66046] lib: Migrate `.isCdata` lookup from a linear loop to a hash table lookup by hartwork Β· Pull Request #1321 Β· lβ¦
Everything after the next line is the original report Markdownβ¦
Quadratic CPU Complexity in storeAtts() isCdata Attribute Default Lookup
Package: libexpat/libexpat
Tested Versions: 2.8.2 / master ...
Quadratic CPU Complexity in storeAtts() isCdata Attribute Default Lookup
Package: libexpat/libexpat
Tested Versions: 2.8.2 / master ...
π¨ CVE-2026-66621
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ultimate Dashboard Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66629
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Kirki Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66633
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Fluent Forms Pro Add On Pack Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66634
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
π@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Modal Survey Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66635
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Slider by 10Web Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66636
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Wise Chat Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66637
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Featured Video Plus Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66638
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Frontend Admin by DynamiApps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66639
Contributor Cross Site Scripting (XSS) in WPZOOM Forms β Contact Form Plugin for Gutenberg <= 2.0.4 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in WPZOOM Forms β Contact Form Plugin for Gutenberg <= 2.0.4 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WPZOOM Forms β Contact Form Plugin for Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66640
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Login With Ajax Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66641
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Video Conferencing with Zoom Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66643
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Wufoo Shortcode Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66644
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Typing Effect Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66645
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Table Of Contents Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66646
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Tab Widget Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.