3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81625 — A remote attacker with user privileges may use a malicious or compromised NASL vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81625

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81581 — This usually results in a denial of service, yet we cannot rule out the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81581

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges). CVSSv3.1 8.8 (HIGH)

CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81579 — WibuKey: In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81579

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system. CVSSv3.1 8.8 (HIGH)

CWECWE 123VNDWibukeyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81574 — CodeMeter: In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81574

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then trigge CVSSv3.1 8.2 (HIGH)

CWECWE 134VNDCodemeterTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81573 — CodeMeter: If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81573

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. CVSSv3.1 8.6 (HIGH)

CWECWE 284VNDCodemeterTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81277 — Contributor: SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81277

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81273 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81273

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 352TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-81271 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81271

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78292 — PHP: Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78292

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78288 — SQL: Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78288

Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78286 — PHP: Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78286

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-78285 — Subscriber: SQL Injection in Like Button Rating <= 2.6.61 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78285

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78274 — Editor: Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78274

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDEditorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-78260 — SQL: Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78260

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-78257 — Contributor: PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78257

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-75020 — Apache Apisix: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75020

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. CVSSv3.1 8.1 (HIGH) · EPSS 41th percentile

CWECWE 90VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-59354 — Spring: In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59354

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may res CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDSpringTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-32566 — Privilege: Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32566

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-32564 — Subscriber: SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32564

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-32550 — Subscriber: SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32550

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 10:16Z
CRIT

CVE-2026-32479 — SQL: Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32479

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-27 10:16Z
HIGH

CVE-2026-27330 — Broken: Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27330

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-78333 — Step: The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78333

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
HIGH

CVE-2026-77018 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77018

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDWorkeeraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-27 06:17Z
CRIT

CVE-2026-77016 — Workeera: The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77016

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73VNDWorkeeraTYPVulnerability
9.6
CVSS v3.1
98
Edit Score