π¨ CVE-2026-75602
OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temporary filename comes from the attacker-controlled Content-Disposition header, is passed from parseFilenameFromContentDisposition in internal/offline_download/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/client.go, and is opened with os.Create without a containment check. Because filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDownload on any path can traverse out of task.TempDir and create, truncate, or overwrite any file writable by the OpenList process whose parent directory already exists. The server/handles/offline_download.go AddOfflineDownload route uses normal user authentication rather than AuthAdmin, and local-storage destinations fall through tryPutUrl in internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version 4.2.3.
π@cveNotify
OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temporary filename comes from the attacker-controlled Content-Disposition header, is passed from parseFilenameFromContentDisposition in internal/offline_download/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/client.go, and is opened with os.Create without a containment check. Because filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDownload on any path can traverse out of task.TempDir and create, truncate, or overwrite any file writable by the OpenList process whose parent directory already exists. The server/handles/offline_download.go AddOfflineDownload route uses normal user authentication rather than AuthAdmin, and local-storage destinations fall through tryPutUrl in internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version 4.2.3.
π@cveNotify
GitHub
fix(offline_download): block SimpleHttp temp file path traversal via β¦ Β· OpenListTeam/OpenList@9cc5dd9
β¦strict filename sanitization
* fix(offline_download): prevent path traversal
* fix(SimpleHttp): improve filename validation
* fix(offline_download): harden SimpleHttp filename and temp path che...
* fix(offline_download): prevent path traversal
* fix(SimpleHttp): improve filename validation
* fix(offline_download): harden SimpleHttp filename and temp path che...
π¨ CVE-2026-81281
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
π@cveNotify
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Graphene Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81773
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Forms File Uploads Extension Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84753
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Mail Mint Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84758
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
π@cveNotify
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
π@cveNotify
π¨ CVE-2026-84766
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
π@cveNotify
π¨ CVE-2026-84812
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress BP Better Messages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84847
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
π@cveNotify
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
π@cveNotify
π¨ CVE-2026-85305
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery.
This issue affects SEOPress: from n/a through 10.1.
π@cveNotify
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery.
This issue affects SEOPress: from n/a through 10.1.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress SEOPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-85309
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
π@cveNotify
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
π@cveNotify
π¨ CVE-2026-82023
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
π@cveNotify
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
π@cveNotify
WordPress.org
LearnPress β WordPress LMS Plugin for Create and Sell Online Courses
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am β¦
π¨ CVE-2026-79419
A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.
π@cveNotify
A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.
π@cveNotify
π¨ CVE-2026-33630
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw β a query's callback being invoked while the query is still linked in the channel's internal lookup structures β is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.
π@cveNotify
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw β a query's callback being invoked while the query is still linked in the channel's internal lookup structures β is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.
π@cveNotify
GitHub
Merge commit from fork Β· c-ares/c-ares@1fa3b86
* Fix double-free in process_timeouts() when ares_cancel() called from callback
Detach query from queries_by_qid and all_queries before invoking
callback to prevent ares_cancel() from finding and ...
Detach query from queries_by_qid and all_queries before invoking
callback to prevent ares_cancel() from finding and ...
π¨ CVE-2026-85390
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.
π@cveNotify
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.
π@cveNotify
GitHub
GitHub - bluewave-labs/Checkmate: Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware,β¦
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Don't be shy, ...
π¨ CVE-2026-85395
UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.
π@cveNotify
UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.
π@cveNotify
GitHub
oss/unopim.md at main Β· geo-chen/oss
securing oss responsibly. Contribute to geo-chen/oss development by creating an account on GitHub.
π¨ CVE-2026-85207
A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
π@cveNotify
GitHub
202607_vul_dir/H-06-XSS-Reflected-OrderDetails_en.md at main Β· boyslikesports/202607_vul_dir
2026εΉ΄7ζζηζΌζ΄. Contribute to boyslikesports/202607_vul_dir development by creating an account on GitHub.
π¨ CVE-2026-63376
toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.
π@cveNotify
toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.
π@cveNotify
GitHub
fix: prevent prototype traversal during table resolution Β· BinaryMuse/toml-node@def6ab5
TOML parser for Node.js and the Browser. Parses TOML v1.1.0 - fix: prevent prototype traversal during table resolution Β· BinaryMuse/toml-node@def6ab5
π¨ CVE-2026-9736
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
π@cveNotify
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
π@cveNotify
Ibm
Security Bulletin: Vulnerabilities exists in IBM Netezza Software
Vulnerabilities identified in IBM Netezza Software have been addressed in version 11.3.1.3.
π¨ CVE-2026-85225
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
π@cveNotify
π¨ CVE-2026-85424
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
π@cveNotify
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
π@cveNotify
GitHub
GitHub - themoos/core-moos: A very light weight, easy to use middleware. You will need core-moos above all other components
A very light weight, easy to use middleware. You will need core-moos above all other components - themoos/core-moos
π¨ CVE-2026-85429
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
π@cveNotify
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
π@cveNotify
GitHub
GitHub - moos-ivp/moos-ivp: MOOS-IvP is a set of modules for providing autonomy on robotic platforms, in particular autonomousβ¦
MOOS-IvP is a set of modules for providing autonomy on robotic platforms, in particular autonomous marine vehicles. - moos-ivp/moos-ivp