Common Vulnerabilities and Exposures (CVE)

CVE-2026-76789

Aug 22, 2026 06:00:17 UTC

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated ...

CVE-2026-19222

Aug 22, 2026 06:00:17 UTC

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role...

CVE-2026-19221

Aug 22, 2026 06:00:16 UTC

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire netwo...

CVE-2026-19093

Aug 22, 2026 06:00:16 UTC

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The rea...

CVE-2026-18052

Aug 22, 2026 06:00:16 UTC

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link ...

CVE-2026-16738

Aug 22, 2026 06:00:16 UTC

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticate...

CVE-2026-16612

Aug 22, 2026 06:00:16 UTC

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their...

CVE-2026-16260

Aug 22, 2026 06:00:15 UTC

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contribut...

CVE-2026-14187

Aug 22, 2026 06:00:15 UTC

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

CVE-2026-77781

Aug 22, 2026 04:12:19 UTC

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match whe...

CVE-2026-64531

Aug 22, 2026 04:12:18 UTC

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openv...

CVE-2026-69555

Aug 22, 2026 03:56:44 UTC

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69400

Aug 22, 2026 03:56:43 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-16989

Aug 22, 2026 03:56:42 UTC

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.

CVE-2026-55013

Aug 22, 2026 03:56:41 UTC

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.