Common Vulnerabilities and Exposures (CVE)

CVE-2026-78325

Sep 7, 2026 11:47:32 UTC

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google...

CVE-2026-86301

Sep 7, 2026 11:45:06 UTC

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads t...

CVE-2026-86404

Sep 7, 2026 11:35:04 UTC

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method...

CVE-2026-86300

Sep 7, 2026 11:30:09 UTC

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been pu...

CVE-2026-2390

Sep 7, 2026 11:27:25 UTC

The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images' function using a flawed rege...

CVE-2026-81295

Sep 7, 2026 11:17:29 UTC

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

CVE-2026-84238

Sep 7, 2026 11:17:29 UTC

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

CVE-2026-84756

Sep 7, 2026 11:17:29 UTC

Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

CVE-2026-84763

Sep 7, 2026 11:17:28 UTC

Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

CVE-2026-84769

Sep 7, 2026 11:17:28 UTC

Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

CVE-2026-84778

Sep 7, 2026 11:17:28 UTC

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

CVE-2026-84834

Sep 7, 2026 11:17:28 UTC

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

CVE-2026-85302

Sep 7, 2026 11:17:28 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a thr...

CVE-2026-85308

Sep 7, 2026 11:17:28 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

CVE-2026-11613

Sep 7, 2026 11:17:28 UTC

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include ...