Skip to content

Menu
  • Home
Menu

CVE-2026-15369 – Custom User Registration Fields for WooCommerce <= 2.2.3 – Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

Posted on August 30, 2026

CVE ID :CVE-2026-15369 Published : Aug. 29, 2026, 8:16 p.m. | 4 hours, 19 minutes ago Description :The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions…

CVE-2026-82475 – iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check

Posted on August 30, 2026

CVE ID :CVE-2026-82475 Published : Aug. 29, 2026, 5:18 p.m. | 7 hours, 18 minutes ago Description :iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate…

CVE-2026-82473 – KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints

Posted on August 30, 2026

CVE ID :CVE-2026-82473 Published : Aug. 29, 2026, 5:17 p.m. | 7 hours, 18 minutes ago Description :KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers…

CVE-2026-82466 – Rodauth before 2.46.0 Authentication Bypass via webauthn_login

Posted on August 30, 2026

CVE ID :CVE-2026-82466 Published : Aug. 29, 2026, 5:17 p.m. | 7 hours, 18 minutes ago Description :Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to…

CVE-2026-82463 – pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check

Posted on August 30, 2026

CVE ID :CVE-2026-82463 Published : Aug. 29, 2026, 5:17 p.m. | 7 hours, 18 minutes ago Description :pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic….

CVE-2026-55848 – mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types

Posted on August 29, 2026

CVE ID :CVE-2026-55848 Published : Aug. 28, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16,…

CVE-2026-55764 – Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

Posted on August 29, 2026

CVE ID :CVE-2026-55764 Published : Aug. 28, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role…

CVE-2026-81532 – BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corruption

Posted on August 29, 2026

CVE ID :CVE-2026-81532 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver…

CVE-2026-75118 – http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow

Posted on August 29, 2026

CVE ID :CVE-2026-75118 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient…

CVE-2026-55763 – Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits

Posted on August 29, 2026

CVE ID :CVE-2026-55763 Published : Aug. 28, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls…

Posts pagination

1 2 … 136 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme