1d ago
2026-09-12 06:16Z
HIGH

CVE-2026-80491 — SAMO: The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80491

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDSamoTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-77006 — WebTotem: The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77006

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73VNDWebtotemTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-77005 — CODE: The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77005

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover. CVSSv3.1 9.6 (CRITICAL)

CWECWE 73VNDCodeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1d ago
2026-09-12 06:16Z
CRIT

CVE-2026-75800 — Frontegg: The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75800

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDFronteggTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-12 03:16Z
CRIT

CVE-2026-87719 — GitLab: has remediated an issue in GitLab EE affecting all versions from 18.3 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87719

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup. CVSSv3.1 9.9 (CRITICAL)

CWECWE 502VNDGitlabTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1d ago
2026-09-12 03:16Z
CRIT

CVE-2026-85706 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85706

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. CVSSv3.1 10.0 (CRITICAL)

CWECWE 22VNDGitlabTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-09-12 00:17Z
HIGH

CVE-2026-89266 — stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89266

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption. CVSSv3.1 8.2 (HIGH)

CWECWE 787TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
1d ago
2026-09-11 21:17Z
HIGH

CVE-2026-54174 — melange allows users to build apk packages using declarative pipelines.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54174

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary file contents while the control hash check still CVSSv3.1 8.3 (HIGH)

CWECWE 345CWECWE 354TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1d ago
2026-09-11 21:17Z
HIGH

CVE-2026-49464 — Portal: NL Portal Backend Libraries provide backend components for Dutch government portals that interact with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49464

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPortalTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-09-11 20:20Z
HIGH

CVE-2026-89744 — Linux: In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89744

In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, FWa3} (Secondary fwnode) FWb: {FWb1, FWb2} In this case: ┌─> fwnode_ge CVSSv3.1 8.4 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1d ago
2026-09-11 20:20Z
HIGH

CVE-2026-89729 — Linux: In the Linux kernel, the following vulnerability has been resolved: HID: sensor-hub: Fix out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89729

In the Linux kernel, the following vulnerability has been resolved: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature sensor_hub_get_feature() clamps its return value to the caller's buffer size, but the copy loop still copies field->report_size / 8 bytes for each report value. A malicious HID descriptor can advertise a large feature field size while an IIO caller supplies a small stack buffer, such as a single s32, causing an out-of-bounds write. HID core CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-11 20:20Z
HIGH

CVE-2026-89725 — Linux: In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89725

In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent out-of-bounds write on RX overflow stm32_rx_done() appends each received CEC byte to rx_msg.msg[] using rx_msg.len as the write index, incrementing it on every RXBR (receive-byte-ready) interrupt without checking it against the buffer size: cec->rx_msg.msg[cec->rx_msg.len++] = val & 0xFF; rx_msg.msg[] is a fixed CEC_MAX_MSG_SIZE (16) byte array in struct cec_msg, and rx_msg.len CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89713 — Linux: In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89713

In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at CVSSv3.1 9.1 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89712 — Linux: In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89712

In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
HIGH

CVE-2026-89711 — Linux: In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89711

In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumption that justified adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is invalid (in the case of NFS reexport). When NFSD exports an NFS filesystem it is very possible for nfsd_mode_check() to encounter a @dentry that doesn't have i_ CVSSv3.1 8.2 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-09-11 20:19Z
HIGH

CVE-2026-89709 — Linux: The pointer targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's .text, so

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89709

In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsvc_ops is published by nfsd_lockd_init() and cleared by nfsd_lockd_shutdown() with plain stores, while lockd dereferences it unguarded from dispatch sites in fs/lockd/svcsubs.c. The pointer targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's .text, so a stale load after rmmod nfsd results in either a NULL deref or a module-text use-after-free CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89708 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89708

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still holds an inflight callback rpc_task that dereferences clp->cl_cb_session. nfsd4_probe_callback_sync() flushes cl_callback_wq, but once nfsd4_run_cb_work() has called rpc_call_async() the rpc_task lives on rpciod; flushing the workqueue does no CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89703 — Linux: revoke_delegation() uses this flag to detect whether FREE_STATEID has already processed the delegation --

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89703

In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked delegations but does not set SC_STATUS_FREED before releasing cl_lock. revoke_delegation() uses this flag to detect whether FREE_STATEID has already processed the delegation -- without it, the freed delegation is added to cl_revoked via list_add(), producing a use-after-free CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89702 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89702

In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it from xpt_local using xpt_locallen: TP_STRUCT__entry( ... __sockaddr(server, rqstp->rq_xprt->xpt_remotelen) ... ) TP_fast_assign( ... __assign_sockaddr(server CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89697 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89697

In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This causes nfsd_setattr() to skip fh_want_write(), so notify_change() runs without a mount write reference. Add the missing fh_want_write() call after the early fh_verify(). CVSSv3.1 9.1 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89689 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89689

In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in use nfsd4_sequence() can free the very slot it is currently processing. When the session shrinker has reduced se_target_maxslots below se_fchannel.maxreqs, the shrink path checks three conditions before calling free_session_slots(): 1. se_target_maxslots < maxreqs (shrink was advertised) 2. slot->sl_generation == se_slot_gen (slot is up-to-date) 3. s CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89688 — Linux: The error handling nevertheless called nfs4_put_stateowner(stp->st_stateowner), dropping an so_count reference the function never acquired

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89688

In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd4_cstate_assign_replay() returns -EAGAIN (the replay owner is being torn down, R CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89686 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89686

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and triggering the BUG_ON. This race is client-reachable: two NFS clients can trigger it b CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-09-11 20:19Z
HIGH

CVE-2026-89682 — Linux: The global shrinker, laundrette, and fsnotify callbacks can still be inside nfsd_file_dispose_list_delayed() dereferencing that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89682

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads via a per-net freeme queue, preventing the shrinker and GC worker from bearing the cost of closing files (see ffb402596147). However, the queue lives in a separately-allocated struct nfsd_fcache_disposal that is freed by nfsd_free_fcache_disposal_net() during per-net CVSSv3.1 8.1 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-09-11 20:19Z
CRIT

CVE-2026-89681 — Linux: In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89681

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference race The workqueue core clears WORK_STRUCT_PENDING before the callback is invoked, so delayed_work_pending() in lm_breaker_timedout() can return false while the fence worker is already running. This lets the breaker take a duplicate sc_count reference and schedule a new worker that coalesces with the in-progress one. The extra reference is never put, leaking th CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score