๐จ CVE-2026-81758
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
๐@cveNotify
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress OwnerRez API Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81762
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
๐@cveNotify
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Booking and Rental Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81763
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
๐@cveNotify
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Throws SPAM Away Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81764
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Email Essentials Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81765
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Tailored Tools Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81768
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Super Store Finder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81778
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Kalles Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81779
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
This issue affects Newspapers X: from 1.0.46 through 1.0.48.
๐@cveNotify
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
This issue affects Newspapers X: from 1.0.46 through 1.0.48.
๐@cveNotify
Patchstack
Backdoor in WordPress Newspapers X Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82221
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82224
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
๐@cveNotify
๐จ CVE-2026-82225
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82226
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Tickera Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82228
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
๐@cveNotify
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
๐@cveNotify
Patchstack
Bypass Vulnerability in WordPress SiteGround Security Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82229
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WordPress Social Login and Register Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82852
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
๐@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress MapSVG Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82906
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
Poc/sdcb-chats/chats-poc-2.md at main ยท yaowenxiao721/Poc
Contribute to yaowenxiao721/Poc development by creating an account on GitHub.
๐จ CVE-2026-82908
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
๐จ CVE-2026-82909
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.
๐@cveNotify
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.
๐@cveNotify
GitHub
GitHub - QuantumNous/new-api: A unified AI model hub for aggregation & distribution. It supports cross-converting various LLMsโฆ
A unified AI model hub for aggregation & distribution. It supports cross-converting various LLMs into OpenAI-compatible, Claude-compatible, or Gemini-compatible formats. A centralized gatew...
๐จ CVE-2026-82914
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
uvxbywu62qm.feishu.cn
Docs
๐จ CVE-2026-82919
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
Vulnerability Database
CVE-2026-82919 in silicon
A vulnerability was identified in cu silicon up to 0.1.5. This vulnerability is listed as CVE-2026-82919.
๐จ CVE-2026-82921
A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
uvxbywu62qm.feishu.cn
Docs