CVE ID :CVE-2026-78050 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file…
CVE-2026-16149 – Security Hardener <= 2.4.4 – Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite
CVE ID :CVE-2026-16149 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,…
CVE-2026-0551 – PPWP – Password Protect Pages <= 1.9.18 – Authenticated (Contributor+) PHP Object Injection via post_protection_roles
CVE ID :CVE-2026-0551 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions…
CVE-2026-78122 – docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
CVE ID :CVE-2026-78122 Published : Aug. 22, 2026, 11:16 p.m. | 1 hour, 18 minutes ago Description :docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment…
CVE-2026-4703 – WS Form LITE <= 1.10.80 – Unauthenticated PHP Object Injection via Form Submission
CVE ID :CVE-2026-4703 Published : Aug. 22, 2026, 4:16 p.m. | 8 hours, 18 minutes ago Description :The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to…
CVE-2026-48106 – Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
CVE ID :CVE-2026-48106 Published : Aug. 21, 2026, 11:16 p.m. | 1 hour, 17 minutes ago Description :Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise’s cluster replication…
CVE-2026-48105 – Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
CVE ID :CVE-2026-48105 Published : Aug. 21, 2026, 11:16 p.m. | 1 hour, 17 minutes ago Description :Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise’s Raft FSM…
CVE-2026-48050 – Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
CVE ID :CVE-2026-48050 Published : Aug. 21, 2026, 11:16 p.m. | 1 hour, 17 minutes ago Description :Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go’s `net/http/pprof` handlers…
CVE-2026-53530 – ratex-parser panics on `verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
CVE ID :CVE-2026-53530 Published : Aug. 21, 2026, 10:16 p.m. | 2 hours, 17 minutes ago Description :RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser…
CVE-2026-53528 – FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter
CVE ID :CVE-2026-53528 Published : Aug. 21, 2026, 10:16 p.m. | 2 hours, 17 minutes ago Description :LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset…