1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-81737 — FAQ: The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81737

The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDFaqTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-80467 — Advanced: The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80467

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 06:17Z
CRIT

CVE-2026-78657 — SigmaForms: The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78657

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDSigmaformsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-19116 — User: The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19116

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-14357 — DevKit: The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14357

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessibl CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevkitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-12526 — Advanced: The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12526

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing administrator (a fixed target, or one mapped to a visitor-submitted field) and map CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 05:17Z
CRIT

CVE-2026-9055 — Booking: The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9055

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticate CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDBookingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-02 05:17Z
HIGH

CVE-2024-35585 — Oxford: Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-35585

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDOxfordTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-02 03:16Z
HIGH

CVE-2026-14982 — File: The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14982

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The two-stage exploit requires a first request to the file.save task to persist CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 02:17Z
HIGH

CVE-2026-84715 — FeatherPanel: A subuser with minimal permissions can send a crafted request to grant themselves full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84715

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDFeatherpanelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84700 — PikiwiDB: (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84700

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does not require a completed or attempted CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDPikiwidbTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-02 01:17Z
CRIT

CVE-2026-84699 — Team: Unauthenticated attackers can reset local account passwords and authenticate as those users to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84699

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. CVSSv3.1 9.1 (CRITICAL)

CWECWE 640VNDTeamTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84696 — Phison: Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84696

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDPhisonTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84695 — BookStack: before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84695

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDBookstackTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84694 — Coolify: before 4.2.0 fails to properly escape environment variable key names in Docker commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84694

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 00:18Z
CRIT

CVE-2026-84354 — Incorrect: authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84354

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 863TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-02 00:18Z
CRIT

CVE-2026-84353 — Use: after free in Shared Tab Groups in Google Chrome on on Android prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84353

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-02 00:18Z
CRIT

CVE-2026-84352 — Use: after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84352

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84351 — Buffer: overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84351

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 121VNDBufferTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84350 — Use: after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84350

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84349 — Use: after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84349

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84347 — Use: after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84347

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84335 — Incorrect: authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84335

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 863TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 00:18Z
HIGH

CVE-2026-84334 — Incorrect: authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84334

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 00:18Z
CRIT

CVE-2026-84333 — Use: after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84333

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score