Common Vulnerabilities and Exposures (CVE)

CVE-2026-97363

Oct 3, 2026 15:52:54 UTC

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorize...

CVE-2026-95102

Oct 3, 2026 15:52:54 UTC

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. ...

CVE-2026-94594

Oct 3, 2026 15:52:54 UTC

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the lo...

CVE-2026-94593

Oct 3, 2026 15:52:54 UTC

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when...

CVE-2026-94592

Oct 3, 2026 15:52:54 UTC

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server o...

CVE-2026-94591

Oct 3, 2026 15:52:54 UTC

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the so...

CVE-2026-84411

Oct 3, 2026 15:52:53 UTC

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitr...

CVE-2026-105105

Oct 3, 2026 15:52:53 UTC

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message ...

CVE-2026-92245

Oct 3, 2026 15:42:53 UTC

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to ext...

CVE-2026-91109

Oct 3, 2026 15:42:53 UTC

The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. T...

CVE-2026-92548

Oct 3, 2026 15:42:52 UTC

The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. This makes it possible for unauthenticated attackers to extract sensitive edi...

CVE-2026-12241

Oct 3, 2026 15:42:52 UTC

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_meta_boxes' function in all versions up to, ...

CVE-2026-85679

Oct 3, 2026 15:42:52 UTC

The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possibl...

CVE-2026-88999

Oct 3, 2026 15:42:52 UTC

The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi...

CVE-2026-89047

Oct 3, 2026 15:42:52 UTC

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This ...