Common Vulnerabilities and Exposures (CVE)

CVE-2026-15985

Aug 26, 2026 11:36:39 UTC

The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login...

CVE-2026-63041

Aug 26, 2026 11:34:59 UTC

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plu...

CVE-2026-56144

Aug 26, 2026 11:16:24 UTC

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized t...

CVE-2026-18080

Aug 26, 2026 11:05:44 UTC

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing ...

CVE-2026-3235

Aug 26, 2026 11:05:44 UTC

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it pos...

CVE-2026-5092

Aug 26, 2026 11:05:43 UTC

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API ...

CVE-2026-77532

Aug 26, 2026 11:01:30 UTC

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.

CVE-2021-47644

Aug 26, 2026 11:00:35 UTC

In the Linux kernel, the following vulnerability has been resolved: media: staging: media: zoran: move videodev alloc Move some code out of zr36057_init() and create new functions for handling zr->video_dev. This permit to ease code readi...

CVE-2020-36785

Aug 26, 2026 11:00:34 UTC

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a dou...

CVE-2026-77557

Aug 26, 2026 10:53:27 UTC

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.

CVE-2026-77554

Aug 26, 2026 10:45:46 UTC

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.

CVE-2026-77553

Aug 26, 2026 10:42:54 UTC

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

CVE-2026-77552

Aug 26, 2026 10:40:05 UTC

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.

CVE-2026-77551

Aug 26, 2026 10:37:19 UTC

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.

CVE-2026-77550

Aug 26, 2026 10:33:29 UTC

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.