CVE ID :CVE-2026-18855 Published : Aug. 15, 2026, 8:11 p.m. | 4 hours, 1 minute ago Description :The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…
CVE-2026-19598 – Pods <= 3.3.9 – Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
CVE ID :CVE-2026-19598 Published : Aug. 15, 2026, 5:25 p.m. | 6 hours, 47 minutes ago Description :The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via…
CVE-2026-19900 – LB-LINK X-PRO shadow hard-coded credentials
CVE ID :CVE-2026-19900 Published : Aug. 15, 2026, 5:16 p.m. | 6 hours, 56 minutes ago Description :A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the…
CVE-2026-19901 – LB-LINK X-PRO easycwmp hard-coded credentials
CVE ID :CVE-2026-19901 Published : Aug. 15, 2026, 5:15 p.m. | 6 hours, 58 minutes ago Description :A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the…
CVE-2026-18500 – @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key
CVE ID :CVE-2026-18500 Published : Aug. 15, 2026, 2:17 p.m. | 9 hours, 56 minutes ago Description :@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key…
CVE-2026-73683 – Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay
CVE ID :CVE-2026-73683 Published : Aug. 14, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :Laravel Socialite’s Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC…
CVE-2026-73682 – Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling
CVE ID :CVE-2026-73682 Published : Aug. 14, 2026, 9:17 p.m. | 2 hours, 54 minutes ago Description :Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url…
CVE-2026-73680 – Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename
CVE ID :CVE-2026-73680 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated…
CVE-2026-71571 – Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11
CVE ID :CVE-2026-71571 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda Severity: 8.6 |…
CVE-2026-67365 – Joomla Extension – icagenda.com – Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
CVE ID :CVE-2026-67365 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Joomla Extension – icagenda.com – Unauthenticated SQL injection in iCagenda Severity: 9.2 | CRITICAL Visit the link…