4d ago
2026-09-09 09:17Z
HIGH

CVE-2026-87766 — A flaw was found in bubblewrap.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87766

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. CVSSv3.1 8.8 (HIGH)

CWECWE 59TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 09:17Z
HIGH

CVE-2026-80099 — Newfold: Several Newfold plugins are vulnerable to Authentication Bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80099

Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when `HiiveConnection::get_auth_token()` returns `false`: PHP coerces `strrev(false)` to `strrev('')`, c CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDNewfoldTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4d ago
2026-09-09 09:17Z
HIGH

CVE-2026-78491 — Dell: An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78491

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. CVSSv3.1 8.2 (HIGH)

CWECWE 295VNDDellTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4d ago
2026-09-09 09:17Z
CRIT

CVE-2026-16272 — Use: PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16272

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 348TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4d ago
2026-09-09 09:17Z
HIGH

CVE-2026-14359 — YITH: The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14359

The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['params'] that are then passed to wp_create_user() and $user->set_role(). This make CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDYithTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 06:17Z
HIGH

CVE-2026-84068 — Quentn: The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84068

The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDQuentnTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-09 06:17Z
HIGH

CVE-2026-76009 — Next: The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76009

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option('nextcart_token', '__token__')` when the `nextcart_token` option has not yet be CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-09 06:17Z
HIGH

CVE-2026-14962 — ELEX: The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14962

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDElexTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-09 05:17Z
CRIT

CVE-2026-21096 — Samsung Android: Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21096

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 122VNDSamsungVNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 05:17Z
CRIT

CVE-2026-21095 — Samsung Android: Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21095

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 122VNDSamsungVNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-09 05:17Z
HIGH

CVE-2026-21094 — Samsung Android: Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21094

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory. CVSSv3.1 8.8 (HIGH) · EPSS 3th percentile

CWECWE 20VNDSamsungTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 04:19Z
HIGH

CVE-2026-6485 — UEFI: BIOS embedded Shell could be used to bypass Secure Boot via shell commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6485

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts. CVSSv3.1 8.2 (HIGH)

CWECWE 489VNDUefiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 04:17Z
HIGH

CVE-2026-49310 — Permission: control vulnerability in the event notification module.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49310

Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CVSSv3.1 8.6 (HIGH)

CWECWE 264TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-09 04:17Z
HIGH

CVE-2026-12855 — Unvalidated: memory boundary could result in arbitrary code execution.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12855

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects. CVSSv3.1 8.2 (HIGH)

CWECWE 20VNDUnvalidatedTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-87075 — Tanium: addressed an improper access controls vulnerability in Comply.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87075

Tanium addressed an improper access controls vulnerability in Comply. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDTaniumTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-87036 — Tanium: addressed an improper access controls vulnerability in Comply.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87036

Tanium addressed an improper access controls vulnerability in Comply. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDTaniumTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-87034 — Tanium: addressed a SQL injection vulnerability in Comply.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87034

Tanium addressed a SQL injection vulnerability in Comply. CVSSv3.1 8.3 (HIGH)

CWECWE 89VNDTaniumTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-87030 — Tanium: addressed a path traversal vulnerability in Comply.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87030

Tanium addressed a path traversal vulnerability in Comply. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDTaniumTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-87023 — Tanium: addressed a path traversal vulnerability in Comply.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87023

Tanium addressed a path traversal vulnerability in Comply. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDTaniumTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
5d ago
2026-09-09 03:17Z
HIGH

CVE-2026-76801 — FireBox: The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76801

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_contents, combined with no sanitization of PHP condition rule values stored via t CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDFireboxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87654 — Buffer: overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87654

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDBufferTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87650 — Out: of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87650

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 125TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87648 — Use: after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87648

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-09 01:17Z
CRIT

CVE-2026-87646 — Use: after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87646

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-09 01:17Z
HIGH

CVE-2026-87644 — Incorrect: authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87644

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 863TYPVulnerability
8.3
CVSS v3.1
92
Edit Score