π¨ CVE-2026-81284
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
π@cveNotify
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress ACF Extended Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81285
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
π@cveNotify
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
π@cveNotify
Patchstack
Denial of Service Attack in WordPress Smush Image Compression and Optimization Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81299
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
π@cveNotify
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress WP Job Portal Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81757
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
π@cveNotify
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
π@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress Rank Math SEO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81760
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS.
This issue affects JetEngine: from n/a through 3.8.14.2.
π@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS.
This issue affects JetEngine: from n/a through 3.8.14.2.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81767
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
π@cveNotify
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Simple Payment Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-82112
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
π@cveNotify
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
π@cveNotify
GitHub
GitHub - houtini-ai/houtini-lm: MCP server that saves Claude Code tokens by delegating bounded tasks to local or cloud LLMs. Worksβ¦
MCP server that saves Claude Code tokens by delegating bounded tasks to local or cloud LLMs. Works with LM Studio, Ollama, vLLM, DeepSeek, Groq, Cerebras. - houtini-ai/houtini-lm
π¨ CVE-2026-82181
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
π@cveNotify
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
π@cveNotify
π¨ CVE-2026-82220
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
π@cveNotify
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
π@cveNotify
Patchstack
Other Vulnerability Type in WordPress Forminator Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-20097
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
π@cveNotify
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary code or commands on the underlying operating system of an affected system andβ¦
π¨ CVE-2026-21548
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
π@cveNotify
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.
π@cveNotify
π¨ CVE-2026-21549
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21550
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21551
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21552
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21553
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21554
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
π¨ CVE-2026-21555
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
π@cveNotify