Skip to content

Menu
  • Home
Menu

CVE-2026-74784 – Scriban before 7.2.0 Denial of Service via array.insert_at

Posted on August 17, 2026

CVE ID :CVE-2026-74784 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null…

CVE-2026-18855 – The Link Library plugin for WordPress is vulnerabl

Posted on August 16, 2026

CVE ID :CVE-2026-18855 Published : Aug. 15, 2026, 8:11 p.m. | 4 hours, 1 minute ago Description :The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…

CVE-2026-19598 – Pods <= 3.3.9 – Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router

Posted on August 16, 2026

CVE ID :CVE-2026-19598 Published : Aug. 15, 2026, 5:25 p.m. | 6 hours, 47 minutes ago Description :The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via…

CVE-2026-19900 – LB-LINK X-PRO shadow hard-coded credentials

Posted on August 16, 2026

CVE ID :CVE-2026-19900 Published : Aug. 15, 2026, 5:16 p.m. | 6 hours, 56 minutes ago Description :A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the…

CVE-2026-19901 – LB-LINK X-PRO easycwmp hard-coded credentials

Posted on August 16, 2026

CVE ID :CVE-2026-19901 Published : Aug. 15, 2026, 5:15 p.m. | 6 hours, 58 minutes ago Description :A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the…

CVE-2026-18500 – @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key

Posted on August 16, 2026

CVE ID :CVE-2026-18500 Published : Aug. 15, 2026, 2:17 p.m. | 9 hours, 56 minutes ago Description :@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key…

CVE-2026-73683 – Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay

Posted on August 15, 2026

CVE ID :CVE-2026-73683 Published : Aug. 14, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :Laravel Socialite’s Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC…

CVE-2026-73682 – Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling

Posted on August 15, 2026

CVE ID :CVE-2026-73682 Published : Aug. 14, 2026, 9:17 p.m. | 2 hours, 54 minutes ago Description :Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url…

CVE-2026-73680 – Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename

Posted on August 15, 2026

CVE ID :CVE-2026-73680 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated…

CVE-2026-71571 – Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11

Posted on August 15, 2026

CVE ID :CVE-2026-71571 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda Severity: 8.6 |…

Posts pagination

Previous 1 … 10 11 12 … 139 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme