Common Vulnerabilities and Exposures (CVE)

CVE-2026-66310

Aug 5, 2026 13:33:33 UTC

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVE-2026-66344

Aug 5, 2026 13:33:27 UTC

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privilege...

CVE-2026-58075

Aug 5, 2026 13:33:25 UTC

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

CVE-2026-18902

Aug 5, 2026 13:32:29 UTC

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Rem...

CVE-2026-71192

Aug 5, 2026 13:31:30 UTC

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request ...

CVE-2026-54416

Aug 5, 2026 13:31:13 UTC

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi...

CVE-2026-5062

Aug 5, 2026 13:30:37 UTC

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to,...

CVE-2026-11454

Aug 5, 2026 13:30:11 UTC

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpo...

CVE-2026-18881

Aug 5, 2026 13:29:54 UTC

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including,...

CVE-2025-15366

Aug 5, 2026 13:29:42 UTC

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

CVE-2026-6079

Aug 5, 2026 13:29:33 UTC

The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This mak...

CVE-2026-7105

Aug 5, 2026 13:29:04 UTC

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authen...

CVE-2026-0864

Aug 5, 2026 13:28:42 UTC

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the writt...

CVE-2026-71207

Aug 5, 2026 13:28:36 UTC

The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameter...

CVE-2026-11940

Aug 5, 2026 13:28:28 UTC

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's ar...