CVE-2026-73366 — PHP: Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. CVSSv3.1 10.0 (CRITICAL)
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. CVSSv3.1 9.3 (CRITICAL)
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation. CVSSv3.1 8.8 (HIGH)
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. CVSSv3.1 9.9 (CRITICAL)
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, an CVSSv3.1 8.8 (HIGH)
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. CVSSv3.1 8.8 (HIGH)
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream CVSSv3.1 9.8 (CRITICAL)
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue i CVSSv3.1 8.8 (HIGH)
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches CVSSv3.1 8.1 (HIGH)
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron CVSSv3.1 8.3 (HIGH)
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. CVSSv3.1 9.9 (CRITICAL)
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. CVSSv3.1 9.8 (CRITICAL)
BloodHound CE v9.6.0 released with 31 commits including UI improvements, API enhancements, dependency updates, and security patches. Notable changes include fixes for CVE-2026-16221 and CVE-2026-67213, upgrades to Go 1.26.6, dompurify 3.4.13, and AzureHound v3.1.0, along with new findings prioritization features and management operation endpoints.
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. CVSSv3.1 8.5 (HIGH)
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. CVSSv3.1 8.1 (HIGH)
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. CVSSv3.1 9.9 (CRITICAL)
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. CVSSv3.1 9.9 (CRITICAL)