Common Vulnerabilities and Exposures (CVE)

CVE-2026-78657

Sep 2, 2026 05:29:52 UTC

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes ...

CVE-2026-14357

Sep 2, 2026 05:29:51 UTC

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registere...

CVE-2026-84232

Sep 2, 2026 05:02:45 UTC

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disp...

CVE-2025-46418

Sep 2, 2026 04:33:34 UTC

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

CVE-2026-9055

Sep 2, 2026 04:26:46 UTC

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in th...

CVE-2024-35585

Sep 2, 2026 04:21:46 UTC

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

CVE-2026-83548

Sep 2, 2026 03:55:59 UTC

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized acc...

CVE-2026-83549

Sep 2, 2026 03:55:58 UTC

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentiall...

CVE-2026-63137

Sep 2, 2026 03:55:57 UTC

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow execution...

CVE-2026-72649

Sep 2, 2026 03:55:56 UTC

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic...

CVE-2026-9586

Sep 2, 2026 03:55:55 UTC

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into Pos...

CVE-2026-49869

Sep 2, 2026 03:55:54 UTC

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Becaus...

CVE-2026-58566

Sep 2, 2026 03:55:53 UTC

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

CVE-2026-58567

Sep 2, 2026 03:55:52 UTC

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

CVE-2026-79687

Sep 2, 2026 03:55:51 UTC

Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.