🚨 CVE-2026-85507
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
🎖@cveNotify
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
🎖@cveNotify
🚨 CVE-2026-85508
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
🎖@cveNotify
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
🎖@cveNotify
🚨 CVE-2026-85509
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
🎖@cveNotify
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
🎖@cveNotify
🚨 CVE-2026-49509
Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers.
This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.
🎖@cveNotify
Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers.
This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.
🎖@cveNotify
GitHub
stb_image: don't deal with fractional ratios by mmaciola · Pull Request #604 · Samsung/rlottie
Apply fix from stb 2.27
🚨 CVE-2025-15691
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
🎖@cveNotify
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
🎖@cveNotify
WPScan
WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms
See details on WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms CVE 2025-15691. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15354
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
🎖@cveNotify
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
🎖@cveNotify
ACPT
ACPT Changelog — Version History
Full version history for ACPT: new features, bug fixes, and improvements across every release of the WordPress custom post types framework.
🚨 CVE-2026-16281
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
🎖@cveNotify
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
🎖@cveNotify
WPScan
Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR
See details on Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR CVE 2026-16281. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17517
The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.
🎖@cveNotify
The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.
🎖@cveNotify
WPScan
Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter
See details on Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter CVE 2026-17517. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19224
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
🎖@cveNotify
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
🎖@cveNotify
WPScan
Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
See details on Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite CVE 2026-19224. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-62928
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🎖@cveNotify
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-66840
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
🎖@cveNotify
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-69657
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-70403
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-71216
PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty serves this endpoint over HTTPS and will
normally answer plain HTTP with a redirect. That does not remove the exposure.
The initial POST -- including the JSON body containing the routing key -- is
written to the socket unencrypted before any redirect response is received.
Redirection affects only whether the request is retried securely, not whether
the first copy left the host in the clear.
This issue affects Apache SkyWalking: from 9.6.0 through 11.0.0.
Users are recommended to upgrade to version 11.0.0, which fixes the issue.
🎖@cveNotify
PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty serves this endpoint over HTTPS and will
normally answer plain HTTP with a redirect. That does not remove the exposure.
The initial POST -- including the JSON body containing the routing key -- is
written to the socket unencrypted before any redirect response is received.
Redirection affects only whether the request is retried securely, not whether
the first copy left the host in the clear.
This issue affects Apache SkyWalking: from 9.6.0 through 11.0.0.
Users are recommended to upgrade to version 11.0.0, which fixes the issue.
🎖@cveNotify
🚨 CVE-2026-74853
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
🎖@cveNotify
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
🎖@cveNotify
WPScan
Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback
See details on Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback CVE 2026-74853. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-79630
The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.
🎖@cveNotify
The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.
🎖@cveNotify
WPScan
WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitution
See details on WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitution CVE 2026-79630. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-79631
The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.
🎖@cveNotify
The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.
🎖@cveNotify
WPScan
WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log Files
See details on WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log Files CVE 2026-79631. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-79632
The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
🎖@cveNotify
The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
🎖@cveNotify
WPScan
WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission
See details on WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission CVE 2026-79632. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-80180
Stored XSS via markdown HTML processing in Apache Allura.
This issue affects Apache Allura: from through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
🎖@cveNotify
Stored XSS via markdown HTML processing in Apache Allura.
This issue affects Apache Allura: from through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
🎖@cveNotify
🚨 CVE-2026-80181
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
🎖@cveNotify
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
🎖@cveNotify
🚨 CVE-2026-80438
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages.
The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.
🎖@cveNotify
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages.
The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.
🎖@cveNotify
WPScan
Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Information Disclosure via Abilities REST…
See details on Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Information Disclosure via Abilities REST API CVE 2026-80438. View the latest Plugin Vulnerabilities on WPScan.