Common Vulnerabilities and Exposures (CVE)

CVE-2026-84849

Sep 3, 2026 17:51:33 UTC

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

CVE-2026-81292

Sep 3, 2026 17:50:49 UTC

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

CVE-2026-84215

Sep 3, 2026 17:49:47 UTC

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

CVE-2026-84755

Sep 3, 2026 17:49:11 UTC

Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.

CVE-2026-77348

Sep 3, 2026 17:43:56 UTC

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cUR...

CVE-2026-84308

Sep 3, 2026 17:41:50 UTC

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). Duri...

CVE-2026-84762

Sep 3, 2026 17:41:42 UTC

Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

CVE-2026-63219

Sep 3, 2026 17:40:21 UTC

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled f...

CVE-2026-84736

Sep 3, 2026 17:38:14 UTC

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALI...

CVE-2026-85242

Sep 3, 2026 17:37:23 UTC

PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, lo...

CVE-2026-77353

Sep 3, 2026 17:37:08 UTC

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequenc...

CVE-2026-81300

Sep 3, 2026 17:36:50 UTC

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

CVE-2026-83605

Sep 3, 2026 17:35:55 UTC

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute() calls the private ...

CVE-2026-84752

Sep 3, 2026 17:35:53 UTC

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

CVE-2026-84757

Sep 3, 2026 17:35:28 UTC

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.