Common Vulnerabilities and Exposures (CVE)

CVE-2026-75905

Sep 9, 2026 05:31:05 UTC

The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it poss...

CVE-2026-8615

Sep 9, 2026 05:31:05 UTC

The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and includ...

CVE-2026-76009

Sep 9, 2026 05:31:04 UTC

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-j...

CVE-2026-83593

Sep 9, 2026 05:31:04 UTC

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient input s...

CVE-2026-84908

Sep 9, 2026 05:31:04 UTC

The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and unauthenticated (wp_a...

CVE-2026-19946

Sep 9, 2026 05:31:03 UTC

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_...

CVE-2026-6893

Sep 9, 2026 05:22:46 UTC

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's...

CVE-2026-16517

Sep 9, 2026 05:14:54 UTC

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addi...

CVE-2026-21113

Sep 9, 2026 04:48:03 UTC

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

CVE-2026-21112

Sep 9, 2026 04:48:02 UTC

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

CVE-2026-21111

Sep 9, 2026 04:48:01 UTC

Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.

CVE-2026-21110

Sep 9, 2026 04:48:00 UTC

Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.

CVE-2026-21109

Sep 9, 2026 04:47:59 UTC

Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.

CVE-2026-21108

Sep 9, 2026 04:47:58 UTC

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

CVE-2026-21107

Sep 9, 2026 04:47:57 UTC

Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.