CVE ID :CVE-2026-90606 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the…
CVE-2026-90605 – Totolink A3002MU boa formFilter buffer overflow
CVE ID :CVE-2026-90605 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file…
CVE-2026-88793 – YouTube Embed 10.0 – 10.3 – Unauthenticated Stored XSS via youram_server
CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one…
CVE-2026-85129 – Hoo Companion 1.0.2 – Unauthenticated Stored XSS via Theme Settings Import
CVE ID :CVE-2026-85129 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of…
CVE-2026-81648 – CryptoPayment Gateway 1.2.1 – 1.2.2 – Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
CVE ID :CVE-2026-81648 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one…
CVE-2026-74933 – GenieWords 1.5.27 – 1.5.34 – Unauthenticated Stored XSS and Configuration Overwrite
CVE ID :CVE-2026-74933 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its…
CVE-2026-37008 – CrewAI Sandbox Bypass via Python Runtime Manipulation
CVE ID :CVE-2026-37008 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a…
CVE-2026-90651 – Socket Firewall TLS Certificate Verification Bypass
CVE ID :CVE-2026-90651 Published : Sept. 13, 2026, 12:17 a.m. | 51 minutes ago Description :Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the…
CVE-2026-90647 – Kalkitech ASE2000 Improper Certificate Validation Vulnerability
CVE ID :CVE-2026-90647 Published : Sept. 12, 2026, 10:38 p.m. | 29 minutes ago Description :ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in…
CVE-2026-90560 – zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress
CVE ID :CVE-2026-90560 Published : Sept. 12, 2026, 6:16 p.m. | 4 hours, 51 minutes ago Description :zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and…