Total
398235 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-79996 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator. | |||||
| CVE-2026-79615 | 2026-08-28 | N/A | 2.7 LOW | ||
| The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. | |||||
| CVE-2026-79706 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. | |||||
| CVE-2026-79995 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's. | |||||
| CVE-2026-14567 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |||||
| CVE-2026-77701 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site. | |||||
| CVE-2026-14558 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site. | |||||
| CVE-2026-59567 | 2026-08-28 | N/A | 8.8 HIGH | ||
| Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | |||||
| CVE-2026-59565 | 2026-08-28 | N/A | 8.8 HIGH | ||
| A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | |||||
| CVE-2026-53414 | 2026-08-28 | N/A | 6.5 MEDIUM | ||
| Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | |||||
| CVE-2026-53413 | 2026-08-28 | N/A | 8.3 HIGH | ||
| Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | |||||
| CVE-2026-59568 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | |||||
| CVE-2026-53415 | 2026-08-28 | N/A | 8.3 HIGH | ||
| Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | |||||
| CVE-2026-59564 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |||||
| CVE-2026-59566 | 2026-08-28 | N/A | 8.4 HIGH | ||
| A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | |||||
| CVE-2026-53416 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. | |||||
| CVE-2026-20090 | 1 Cisco | 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software | 2026-08-28 | N/A | 4.8 MEDIUM |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information. | |||||
| CVE-2026-74899 | 1 Jahlives | 1 Openssl Encrypt | 2026-08-28 | N/A | 9.8 CRITICAL |
| openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands. | |||||
| CVE-2026-20089 | 1 Cisco | 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software | 2026-08-28 | N/A | 4.8 MEDIUM |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information. | |||||
| CVE-2025-36192 | 1 Ibm | 4 Ds8900f, Ds8900f Firmware, Ds8a00 and 1 more | 2026-08-28 | N/A | 6.7 MEDIUM |
| IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy / GDPS Logical corruption protection mechanisms. | |||||
