Common Vulnerabilities and Exposures (CVE)

CVE-2026-81774

Sep 2, 2026 11:37:29 UTC

Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.

CVE-2026-81772

Sep 2, 2026 11:37:29 UTC

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

CVE-2026-81771

Sep 2, 2026 11:37:28 UTC

Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.

CVE-2026-81770

Sep 2, 2026 11:37:27 UTC

Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.

CVE-2026-81294

Sep 2, 2026 11:37:26 UTC

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

CVE-2026-81289

Sep 2, 2026 11:37:25 UTC

Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.

CVE-2026-81288

Sep 2, 2026 11:37:25 UTC

Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.

CVE-2026-81286

Sep 2, 2026 11:37:24 UTC

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

CVE-2026-81283

Sep 2, 2026 11:37:23 UTC

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

CVE-2026-84781

Sep 2, 2026 11:37:23 UTC

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.

CVE-2025-46418

Sep 2, 2026 11:34:07 UTC

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

CVE-2026-17527

Sep 2, 2026 11:32:33 UTC

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone auth...

CVE-2026-84425

Sep 2, 2026 11:15:15 UTC

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The att...

CVE-2026-84694

Sep 2, 2026 11:13:47 UTC

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrar...

CVE-2026-32773

Sep 2, 2026 11:11:30 UTC

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged ...