Common Vulnerabilities and Exposures (CVE)

CVE-2026-26054

Sep 28, 2026 15:33:32 UTC

SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without rec...

CVE-2026-80359

Sep 28, 2026 15:33:31 UTC

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physi...

CVE-2026-89303

Sep 28, 2026 15:32:12 UTC

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

CVE-2026-93000

Sep 28, 2026 15:32:11 UTC

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.

CVE-2026-89300

Sep 28, 2026 15:32:11 UTC

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send template...

CVE-2026-84744

Sep 28, 2026 15:32:11 UTC

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registe...

CVE-2026-86838

Sep 28, 2026 15:32:11 UTC

The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for fr...

CVE-2026-88828

Sep 28, 2026 15:32:11 UTC

The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that accoun...

CVE-2026-89411

Sep 28, 2026 15:32:11 UTC

The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smalle...

CVE-2026-92996

Sep 28, 2026 15:32:11 UTC

The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.

CVE-2026-101077

Sep 28, 2026 15:31:09 UTC

A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit...

CVE-2026-95655

Sep 28, 2026 15:29:10 UTC

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from...

CVE-2026-94387

Sep 28, 2026 15:29:08 UTC

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inje...

CVE-2026-17615

Sep 28, 2026 15:27:32 UTC

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external ent...

CVE-2026-101074

Sep 28, 2026 15:21:44 UTC

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based...