NIST

CVE intelligence

Cached from NVD. 2026-09-19 PT. Recent.

CVETitleVendorPublishedCVSSKEV listed
CVE-2026-86164A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans2026-09-06
CVE-2026-86163A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.p2026-09-06
CVE-2026-86162A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=log2026-09-06
CVE-2026-86161A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?acti2026-09-06
CVE-2026-86160A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php2026-09-06
CVE-2026-86159A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. Th2026-09-06
CVE-2026-86153A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Red2026-09-06
CVE-2026-86152A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddW2026-09-06
CVE-2026-86151A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the comp2026-09-06
CVE-2026-85038The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does n2026-09-06
CVE-2026-84219The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthent2026-09-06
CVE-2026-84028The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attri2026-09-06
CVE-2026-80439The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being2026-09-06
CVE-2026-80437The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when i2026-09-06
CVE-2026-75816The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and 2026-09-06
CVE-2026-75793The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowin2026-09-06
CVE-2026-19862The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form2026-09-06
CVE-2026-19859The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing un2026-09-06
CVE-2026-18480The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission2026-09-06
CVE-2026-18056The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up t2026-09-06
CVE-2026-16310The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'i2026-09-06
CVE-2026-13159The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authe2026-09-06
CVE-2022-51009PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attac2026-09-06
CVE-2022-51008PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without2026-09-06
CVE-2021-48007PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients 2026-09-06
CVE-2021-48006PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function low2026-09-06
CVE-2020-37277PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() meth2026-09-06
CVE-2026-8625The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t2026-09-05
CVE-2026-8623The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t2026-09-05
CVE-2026-86207An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs2026-09-05
CVE-2026-86206A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026-09-05
CVE-2026-86197Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav2026-09-05
CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing u2026-09-05
CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags()2026-09-05
CVE-2026-86194Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to 2026-09-05
CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user manager2026-09-05
CVE-2026-86192SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish reade2026-09-05
CVE-2026-86191SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish r2026-09-05
CVE-2026-86190WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password2026-09-05
CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitr2026-09-05

Previous41–80 of 210Next