Common Vulnerabilities and Exposures (CVE)

CVE-2026-83959

Sep 3, 2026 17:35:22 UTC

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope...

CVE-2026-84765

Sep 3, 2026 17:34:30 UTC

Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.

CVE-2026-84773

Sep 3, 2026 17:34:17 UTC

Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.

CVE-2026-84779

Sep 3, 2026 17:34:02 UTC

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

CVE-2026-84768

Sep 3, 2026 17:33:46 UTC

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

CVE-2026-84836

Sep 3, 2026 17:33:42 UTC

Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

CVE-2026-85303

Sep 3, 2026 17:33:24 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.

CVE-2026-85304

Sep 3, 2026 17:33:06 UTC

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For...

CVE-2026-84968

Sep 3, 2026 17:32:29 UTC

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is ret...

CVE-2026-85012

Sep 3, 2026 17:30:24 UTC

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in ...

CVE-2026-19611

Sep 3, 2026 17:28:05 UTC

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an A...

CVE-2026-84777

Sep 3, 2026 17:27:36 UTC

Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

CVE-2026-84814

Sep 3, 2026 17:25:47 UTC

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

CVE-2026-51686

Sep 3, 2026 17:25:15 UTC

Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVE-2026-51741

Sep 3, 2026 17:25:10 UTC

Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.