5h ago
2026-09-13 12:17Z
HIGH

CVE-2026-90777 — ESPnet: before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90777

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDEspnetTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6h ago
2026-09-13 11:17Z
HIGH

CVE-2026-90770 — Spug: through 3.4.0 contains a remote code execution vulnerability in the ping_check function that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90770

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDSpugTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6h ago
2026-09-13 11:17Z
HIGH

CVE-2026-90768 — CAPEv2: through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90768

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDCapev2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6h ago
2026-09-13 11:17Z
HIGH

CVE-2026-90562 — LangBot: before 4.10.11 generates password recovery keys with only 24 bits of entropy and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90562

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access. CVSSv3.1 8.1 (HIGH)

CWECWE 331VNDLangbotTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6h ago
2026-09-13 11:17Z
HIGH

CVE-2026-90561 — Strapi: versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90561

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDStrapiTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
6h ago
2026-09-13 11:16Z
HIGH

CVE-2026-90510 — The manipulation leads to use of hard-coded cryptographic key .

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90510

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.3 (HIGH)

CWECWE 321CWECWE 320TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
14h ago
2026-09-13 03:16Z
HIGH

CVE-2026-90493 — Tonec: The manipulation results in improper access controls.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90493

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 266CWECWE 284VNDTonecTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
17h ago
2026-09-13 00:17Z
HIGH

CVE-2026-90651 — Socket: An attacker positioned to intercept traffic between Socket Firewall and the Socket API or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90651

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts any certificate, including self-signed and otherwise untrusted certificates, witho CVSSv3.1 8.1 (HIGH)

CWECWE 295VNDSocketTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
23h ago
2026-09-12 18:16Z
HIGH

CVE-2026-90560 — zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90560

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination. CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
23h ago
2026-09-12 18:16Z
CRIT

CVE-2026-90558 — sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90558

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 13:16Z
HIGH

CVE-2026-90537 — WWBN: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-90537

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDWwbnTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-09-12 13:16Z
HIGH

CVE-2026-15451 — MemberPress: The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15451

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-level access and above who hold a corporate account, to create new administrator ac CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDMemberpressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-12 08:16Z
HIGH

CVE-2026-78175 — Tutor: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78175

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token b CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDTutorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-12 08:16Z
CRIT

CVE-2026-78159 — Events: The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78159

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitatio CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDEventsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 08:16Z
CRIT

CVE-2026-78006 — Events: The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78006

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDEventsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-87888 — YayPricing: The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87888

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDYaypricingTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-87759 — Add: The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87759

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDAddTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-85681 — Component: On a single site installation this leads to a full takeover, as registration can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85681

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-84171 — The WP images upload on piclect WordPress plugin through 1.0 does not validate the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84171

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-84099 — WordPress: The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84099

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDWordpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-84047 — Album: The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84047

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDAlbumTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-82845 — Masteriyo: The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82845

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rat CVSSv3.1 9.9 (CRITICAL)

CWECWE 502VNDMasteriyoTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-81742 — REST: The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81742

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDRestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-81402 — Rotator: The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81402

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDRotatorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-80494 — Yogeta: The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80494

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials. CVSSv3.1 8.6 (HIGH)

CWECWE 552VNDYogetaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score