Skip to content

Menu
  • Home
Menu

CVE-2026-105126 – LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering

Posted on October 4, 2026

CVE ID :CVE-2026-105126 Published : Oct. 4, 2026, 12:16 a.m. | 1 hour, 9 minutes ago Description :LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to…

CVE-2026-105123 – W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API

Posted on October 4, 2026

CVE ID :CVE-2026-105123 Published : Oct. 4, 2026, 12:16 a.m. | 1 hour, 9 minutes ago Description :W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary…

CVE-2026-96451 – WordPress Ultimate Member plugin <= 2.13.1 – Privilege Escalation vulnerability

Posted on October 4, 2026

CVE ID :CVE-2026-96451 Published : Oct. 3, 2026, 4:16 p.m. | 7 hours, 9 minutes ago Description :Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects…

CVE-2026-103065 – WordPress Kirki plugin <= 6.3.1 – Arbitrary Code Execution vulnerability

Posted on October 4, 2026

CVE ID :CVE-2026-103065 Published : Oct. 3, 2026, 3:16 p.m. | 8 hours, 9 minutes ago Description :Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly…

CVE-2026-105115 – OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface

Posted on October 4, 2026

CVE ID :CVE-2026-105115 Published : Oct. 3, 2026, 2:16 p.m. | 9 hours, 9 minutes ago Description :OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that…

CVE-2026-105105 – Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

Posted on October 4, 2026

CVE ID :CVE-2026-105105 Published : Oct. 3, 2026, 12:16 p.m. | 11 hours, 8 minutes ago Description :CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core…

CVE-2026-85515 – OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check

Posted on October 4, 2026

CVE ID :CVE-2026-85515 Published : Oct. 3, 2026, 9:17 a.m. | 14 hours, 8 minutes ago Description :In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error…

CVE-2026-105080 – ConvertX Arbitrary Code Execution

Posted on October 3, 2026

CVE ID :CVE-2026-105080 Published : Oct. 3, 2026, 12:39 a.m. | 43 minutes ago Description :In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program…

CVE-2026-104476 – Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive

Posted on October 3, 2026

CVE ID :CVE-2026-104476 Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 6 minutes ago Description :Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export…

CVE-2026-104433 – Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString

Posted on October 3, 2026

CVE ID :CVE-2026-104433 Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 6 minutes ago Description :Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that…

Posts pagination

1 2 … 157 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme