2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-19049 — ProSolution: The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores. CVSSv3.1 8.6 (HIGH) · EPSS 11th percentile

CWECWE 89VNDProsolutionTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-18786 — CheckView: The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18786

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a c CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 287VNDCheckviewTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-18469 — Login: The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18469

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled. CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 287VNDLoginTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-18468 — Login: The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18468

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator. CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 287VNDLoginTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-18030 — BricksForge: The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18030

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account. Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-passwor CVSSv3.1 8.1 (HIGH) · EPSS 4th percentile

CWECWE 862VNDBricksforgeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-17540 — File: The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17540

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service. CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-16985 — Squeeze: The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16985

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution. CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 434VNDSqueezeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-10
2026-08-10 07:16Z
CRIT

CVE-2026-16299 — Single: The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16299

The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-10
2026-08-10 07:16Z
CRIT

CVE-2026-16298 — FoodBoxBooker: The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16298

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 269VNDFoodboxbookerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-16257 — Arvow: The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16257

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information. CVSSv3.1 8.2 (HIGH) · EPSS 5th percentile

CWECWE 287VNDArvowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-14293 — Autopay: The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14293

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page. CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 79VNDAutopayTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-10
2026-08-10 07:16Z
HIGH

CVE-2026-13600 — AutoNetTV: The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials. CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

CWECWE 287VNDAutonettvTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-10
2026-08-10 06:11Z
INFO

Kernel-Exploit-Dojo — CTF kernel exploitation notes, PoCs, exploits, and writeups.

GitHub · kernel exploits·github.comGITHUB POC

Kernel-Exploit-Dojo is a curated GitHub repository containing 100+ Linux kernel exploitation CTF challenges organized by bug class, primitive, and technique. The archive includes exploit code, writeups, and technical documentation covering UAF, heap spraying, pipe_buffer abuse, msg_msg overlaps, modprobe_path overwrites, and privilege escalation primitives across CTF events from 2020–2026.

SRFOsTACTA0004OSLinuxTYPResearchTYPToolSTGPrivescSTGExecutionTECT1548
72
Edit Score
2026-08-09
2026-08-09 11:16Z
CRIT

CVE-2026-19348 — Performing a manipulation of the argument enable/name/mac results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19348

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 10:17Z
HIGH

CVE-2026-19346 — Tenda: This manipulation of the argument Name causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19346

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-09
2026-08-09 07:17Z
HIGH

CVE-2026-19341 — Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19341

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-09
2026-08-09 06:19Z
CRIT

CVE-2026-18473 — Directory: The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18473

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 89TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-09
2026-08-09 06:18Z
HIGH

CVE-2026-17044 — Iptanus: The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17044

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. CVSSv3.1 8.6 (HIGH) · EPSS 7th percentile

CWECWE 89VNDIptanusTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-09
2026-08-09 06:18Z
HIGH

CVE-2026-17017 — CubeWP: The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks. CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

CWECWE 89VNDCubewpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-09
2026-08-09 06:17Z
CRIT

CVE-2026-15038 — InfiniteWP: The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15038

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution. CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile

CWECWE 287VNDInfinitewpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71993 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71993

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71992 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71992

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71991 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71991

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71990 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71990

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71989 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71989

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score