CVE ID :CVE-2026-90896 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions,…
CVE-2026-68489 – Plesk Extensions Ruby and Node.js Toolkit Static Code Injection
CVE ID :CVE-2026-68489 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Static Code Injection in Plesk extensions “Ruby” before 1.6.6 and “Node.js Toolkit” before 2.5.0 allows remote authenticated…
CVE-2026-90606 – Totolink A3002MU boa formIpv6Setup buffer overflow
CVE ID :CVE-2026-90606 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the…
CVE-2026-90605 – Totolink A3002MU boa formFilter buffer overflow
CVE ID :CVE-2026-90605 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file…
CVE-2026-88793 – YouTube Embed 10.0 – 10.3 – Unauthenticated Stored XSS via youram_server
CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one…
CVE-2026-85129 – Hoo Companion 1.0.2 – Unauthenticated Stored XSS via Theme Settings Import
CVE ID :CVE-2026-85129 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of…
CVE-2026-81648 – CryptoPayment Gateway 1.2.1 – 1.2.2 – Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
CVE ID :CVE-2026-81648 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one…
CVE-2026-74933 – GenieWords 1.5.27 – 1.5.34 – Unauthenticated Stored XSS and Configuration Overwrite
CVE ID :CVE-2026-74933 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its…
CVE-2026-37008 – CrewAI Sandbox Bypass via Python Runtime Manipulation
CVE ID :CVE-2026-37008 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a…
CVE-2026-90651 – Socket Firewall TLS Certificate Verification Bypass
CVE ID :CVE-2026-90651 Published : Sept. 13, 2026, 12:17 a.m. | 51 minutes ago Description :Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the…