Common Vulnerabilities and Exposures (CVE)

CVE-2026-66917

Aug 22, 2026 11:50:13 UTC

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

CVE-2026-77988

Aug 22, 2026 11:45:09 UTC

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out...

CVE-2026-4245

Aug 22, 2026 11:30:40 UTC

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capabili...

CVE-2026-3424

Aug 22, 2026 11:30:39 UTC

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action...

CVE-2026-66916

Aug 22, 2026 11:16:35 UTC

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.3.1 - An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protecte...

CVE-2026-77946

Aug 22, 2026 11:00:09 UTC

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation o...

CVE-2026-77945

Aug 22, 2026 10:45:09 UTC

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack ma...

CVE-2026-12505

Aug 22, 2026 09:08:30 UTC

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by...

CVE-2026-8836

Aug 22, 2026 08:42:12 UTC

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters...

CVE-2026-78003

Aug 22, 2026 08:26:38 UTC

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which acce...

CVE-2026-12710

Aug 22, 2026 08:13:00 UTC

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April ...

CVE-2026-77002

Aug 22, 2026 06:00:17 UTC

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrator...

CVE-2026-77001

Aug 22, 2026 06:00:17 UTC

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attac...

CVE-2026-77000

Aug 22, 2026 06:00:17 UTC

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing use...

CVE-2026-76793

Aug 22, 2026 06:00:17 UTC

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to lo...