Subscribe, build a custom feed, or pitch a sponsorship at hello@acadenix.com
Latest intel// live feed
CVE-2026-7313 — Insufficiently: CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization. CVSSv3.1 8.7 (HIGH)
CVE-2026-7312 — Insufficiently: CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuratio CVSSv3.1 10.0 (CRITICAL)
CVE-2026-7201 — CWE: CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users. CVSSv3.1 8.8 (HIGH)
CVE-2026-7198 — CWE: CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations. CVSSv3.1 9.8 (CRITICAL)
CVE-2026-7195 — CWE: CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration. CVSSv3.1 8.8 (HIGH)
CVE-2026-39555 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1. CVSSv3.1 8.1 (HIGH)
CVE-2026-39553 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)
CVE-2026-39552 — Control: Blueprint allows PHP Local File Inclusion.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. CVSSv3.1 8.1 (HIGH)
CVE-2026-10622 — Authentication: Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. CVSSv3.1 8.2 (HIGH)
CVE-2026-10611 — Misp Misp: An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session established during the application beforeFilter phase before the normal login flow enforces the OTP challenge. As a result, an attacker with valid primary authenticatio CVSSv3.1 10.0 (CRITICAL) · EPSS 25th percentile
CVE-2025-69369 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0. CVSSv3.1 8.1 (HIGH)
CVE-2025-68886 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. CVSSv3.1 8.1 (HIGH)
CVE-2025-58897 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0. CVSSv3.1 8.1 (HIGH)
CVE-2025-58707 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. CVSSv3.1 8.1 (HIGH)
CVE-2019-25719 — Infinity: Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the CVSSv3.1 8.6 (HIGH)
CVE-2026-42684 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1. CVSSv3.1 9.3 (CRITICAL)
CVE-2026-39551 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection.
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1. CVSSv3.1 8.1 (HIGH)
CVE-2026-39550 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection.
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6. CVSSv3.1 8.1 (HIGH)
CVE-2025-58705 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12. CVSSv3.1 8.1 (HIGH)
CVE-2025-53440 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)
CVE-2026-5422 — Jupyter Jupyter_server: A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, the to_os_path() function in utils.py does not strip ".." from path parts, enabling CVSSv3.1 8.1 (HIGH)
CVE-2025-53345 — Authorization: Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress
Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3. CVSSv3.1 8.8 (HIGH)
CVE-2025-53209 — Incorrect: Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. CVSSv3.1 9.8 (CRITICAL)
CVE-2026-1784 — Route: The Route OpenShift resource allows to define routes to make pods reachable at a
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration. CVSSv3.1 8.8 (HIGH)
CVE-2026-8206 — Kirki: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address. CVSSv3.1 9.8 (CRITICAL)