π¨ CVE-2026-66610
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Urna Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-66623
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Social Media & Share Icons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-66671
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
π@cveNotify
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
π@cveNotify
Patchstack
Local File Inclusion in WordPress Verdure Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-6017
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
π@cveNotify
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
π@cveNotify
cert.pl
Vulnerabilities in KAON PG5298A/PG5298B routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2025-63080 and CVE-2026-6017) found in KAON PG5298A/PG5298B routers.
π¨ CVE-2026-78246
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
π@cveNotify
GitHub
itsourcecode Online Clinic Management System V1.0 SQL Injection Admin Authentication Bypass Β· Issue #63 Β· microwaveabi/vul
Description The admin login uses htmlspecialchars() with default ENT_COMPAT flag which only escapes double quotes, NOT single quotes. Combined with raw SQL concatenation and MD5 password hashing, t...
π¨ CVE-2026-78258
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
π@cveNotify
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Booking and Rental Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78269
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
π@cveNotify
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Shared Files Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78272
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
π@cveNotify
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Fluent Support Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78277
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
π@cveNotify
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress FluentCRM Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78278
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78279
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Fluent Support Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78280
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Hash Form Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78290
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Magazine Blocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78291
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
π@cveNotify
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress RepairBuddy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78323
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
π@cveNotify
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
π@cveNotify
Redhat
CVE-2026-78323 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2024-21626
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
π@cveNotify
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
π@cveNotify
packetstorm.news
Packet Storm Security
Packet Storm Security provides security news, exploits, advisories, and tools for information security professionals.
π¨ CVE-2023-50176
A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
π@cveNotify
A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
π@cveNotify
π¨ CVE-2025-69223
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
π@cveNotify
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
π@cveNotify
GitHub
Use decompressor max_length parameter (#11898) (#11918) Β· aio-libs/aiohttp@2b920c3
(cherry picked from commit 92477c5a74c43dfe0474bd24f8de11875daa2298)
---------
Co-authored-by: J. Nick Koston <nick@koston.org>
---------
Co-authored-by: J. Nick Koston <nick@koston.org>