Total
397972 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-12513 | 2026-08-28 | N/A | 6.8 MEDIUM | ||
| The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover. | |||||
| CVE-2026-76549 | 2026-08-28 | N/A | 5.9 MEDIUM | ||
| The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link. | |||||
| CVE-2026-20095 | 1 Cisco | 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software | 2026-08-28 | N/A | 6.5 MEDIUM |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a Security Impact Rating (SIR) of High, rather than Medium as the score indicates, because additional security implications could occur once the attacker has become root. | |||||
| CVE-2026-20094 | 1 Cisco | 2 Unified Computing System, Unified Computing System E-series Software | 2026-08-28 | N/A | 8.8 HIGH |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. | |||||
| CVE-2026-12514 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded. | |||||
| CVE-2026-79996 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator. | |||||
| CVE-2026-79615 | 2026-08-28 | N/A | 2.7 LOW | ||
| The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. | |||||
| CVE-2026-79706 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. | |||||
| CVE-2026-79995 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's. | |||||
| CVE-2026-14567 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |||||
| CVE-2026-77701 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site. | |||||
| CVE-2026-14558 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site. | |||||
| CVE-2026-59567 | 2026-08-28 | N/A | 8.8 HIGH | ||
| Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | |||||
| CVE-2026-59565 | 2026-08-28 | N/A | 8.8 HIGH | ||
| A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | |||||
| CVE-2026-53414 | 2026-08-28 | N/A | 6.5 MEDIUM | ||
| Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | |||||
| CVE-2026-53413 | 2026-08-28 | N/A | 8.3 HIGH | ||
| Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | |||||
| CVE-2026-59568 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | |||||
| CVE-2026-53415 | 2026-08-28 | N/A | 8.3 HIGH | ||
| Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | |||||
| CVE-2026-59564 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |||||
| CVE-2026-59566 | 2026-08-28 | N/A | 8.4 HIGH | ||
| A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | |||||
