Common Vulnerabilities and Exposures (CVE)

CVE-2026-19726

Aug 17, 2026 20:10:30 UTC

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including chart...

CVE-2026-16861

Aug 17, 2026 20:09:51 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

CVE-2026-52886

Aug 17, 2026 20:09:32 UTC

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, allow...

CVE-2026-19725

Aug 17, 2026 20:07:51 UTC

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to ...

CVE-2026-67678

Aug 17, 2026 20:07:48 UTC

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

CVE-2026-63667

Aug 17, 2026 20:05:42 UTC

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and exten...

CVE-2026-19717

Aug 17, 2026 20:05:34 UTC

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachme...

CVE-2026-19714

Aug 17, 2026 20:04:22 UTC

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and incl...

CVE-2026-19712

Aug 17, 2026 20:01:58 UTC

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross...

CVE-2025-7639

Aug 17, 2026 20:01:29 UTC

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enter...

CVE-2026-51346

Aug 17, 2026 20:00:38 UTC

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

CVE-2026-50768

Aug 17, 2026 19:57:45 UTC

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

CVE-2026-74234

Aug 17, 2026 19:55:37 UTC

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter di...

CVE-2026-75014

Aug 17, 2026 19:53:30 UTC

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be...

CVE-2026-48053

Aug 17, 2026 19:53:05 UTC

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back t...