Common Vulnerabilities and Exposures (CVE)

CVE-2026-40536

Sep 18, 2026 11:51:29 UTC

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to o...

CVE-2026-93488

Sep 18, 2026 11:47:52 UTC

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can op...

CVE-2026-93493

Sep 18, 2026 11:46:43 UTC

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission ca...

CVE-2026-92714

Sep 18, 2026 11:37:21 UTC

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'e...

CVE-2026-89330

Sep 18, 2026 11:35:19 UTC

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and includin...

CVE-2026-17607

Sep 18, 2026 11:34:07 UTC

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-suppli...

CVE-2026-90981

Sep 18, 2026 11:29:54 UTC

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output es...

CVE-2026-14472

Sep 18, 2026 11:29:01 UTC

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes...

CVE-2026-13623

Sep 18, 2026 11:28:39 UTC

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authent...

CVE-2026-13683

Sep 18, 2026 11:25:20 UTC

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remot...

CVE-2026-56592

Sep 18, 2026 11:24:31 UTC

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the logi...

CVE-2026-81665

Sep 18, 2026 11:23:23 UTC

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A ...

CVE-2026-28199

Sep 18, 2026 11:19:34 UTC

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation c...

CVE-2026-81340

Sep 18, 2026 11:13:38 UTC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the si...

CVE-2026-81810

Sep 18, 2026 11:13:23 UTC

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export th...