Common Vulnerabilities and Exposures (CVE)

CVE-2026-76931

Sep 8, 2026 11:29:59 UTC

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it...

CVE-2026-16502

Sep 8, 2026 11:29:58 UTC

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated att...

CVE-2026-80219

Sep 8, 2026 11:27:54 UTC

A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are deri...

CVE-2026-78234

Sep 8, 2026 11:27:52 UTC

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a...

CVE-2026-77968

Sep 8, 2026 11:27:49 UTC

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the Servic...

CVE-2026-74860

Sep 8, 2026 11:27:45 UTC

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This tr...

CVE-2026-86714

Sep 8, 2026 11:23:06 UTC

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyon...

CVE-2026-86713

Sep 8, 2026 11:23:05 UTC

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers...

CVE-2026-86712

Sep 8, 2026 11:23:05 UTC

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write t...

CVE-2026-86711

Sep 8, 2026 11:23:04 UTC

electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions wit...

CVE-2022-51016

Sep 8, 2026 10:59:26 UTC

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid lo...

CVE-2022-51018

Sep 8, 2026 10:57:05 UTC

PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption ...

CVE-2022-51017

Sep 8, 2026 10:57:00 UTC

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like sk...

CVE-2026-13097

Sep 8, 2026 10:49:24 UTC

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, a...

CVE-2026-77654

Sep 8, 2026 10:44:32 UTC

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate t...