Common Vulnerabilities and Exposures (CVE)

CVE-2026-78435

Aug 24, 2026 21:45:10 UTC

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 lead...

CVE-2026-39458

Aug 24, 2026 21:39:14 UTC

When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software v...

CVE-2026-17113

Aug 24, 2026 21:36:12 UTC

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a ...

CVE-2026-78282

Aug 24, 2026 21:31:35 UTC

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

CVE-2026-78268

Aug 24, 2026 21:31:34 UTC

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

CVE-2026-78267

Aug 24, 2026 21:31:34 UTC

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

CVE-2026-78266

Aug 24, 2026 21:31:33 UTC

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

CVE-2026-78265

Aug 24, 2026 21:31:32 UTC

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

CVE-2026-78263

Aug 24, 2026 21:31:31 UTC

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

CVE-2026-78262

Aug 24, 2026 21:31:30 UTC

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

CVE-2026-78259

Aug 24, 2026 21:31:29 UTC

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

CVE-2026-27364

Aug 24, 2026 21:31:24 UTC

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

CVE-2026-78284

Aug 24, 2026 21:31:23 UTC

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

CVE-2026-78434

Aug 24, 2026 21:30:08 UTC

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulat...

CVE-2026-77337

Aug 24, 2026 21:30:06 UTC

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU o...