Common Vulnerabilities and Exposures (CVE)

CVE-2026-90541

Sep 19, 2026 14:21:55 UTC

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests...

CVE-2026-76451

Sep 19, 2026 14:21:55 UTC

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability ...

CVE-2026-76444

Sep 19, 2026 14:21:55 UTC

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentic...

CVE-2026-76432

Sep 19, 2026 14:21:55 UTC

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability ex...

CVE-2026-20072

Sep 19, 2026 14:21:54 UTC

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to.  ...

CVE-2026-76431

Sep 19, 2026 14:21:54 UTC

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit t...

CVE-2026-87935

Sep 19, 2026 14:21:54 UTC

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_req...

CVE-2026-78296

Sep 19, 2026 14:21:54 UTC

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

CVE-2026-66572

Sep 19, 2026 14:21:54 UTC

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

CVE-2026-66577

Sep 19, 2026 14:21:54 UTC

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

CVE-2026-66617

Sep 19, 2026 14:21:54 UTC

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

CVE-2026-66626

Sep 19, 2026 14:21:53 UTC

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

CVE-2026-73999

Sep 19, 2026 14:21:53 UTC

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

CVE-2026-78294

Sep 19, 2026 14:21:53 UTC

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

CVE-2026-81443

Sep 19, 2026 14:21:53 UTC

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side...