CVE
Recent vulnerabilities tracked in NVD with cybersecurity career impact.
50 items · sorted by most recent
CVE-2026-1255, The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos...
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated use…
CVE-2026-85658, The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User ...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc…
CVE-2026-4327, The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i...
The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' …
CVE-2026-15664, The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for ...
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to …
CVE-2026-92807, The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra...
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()…
CVE-2026-87909, The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut...
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before con…
CVE-2026-13354, The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stor...
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output …
CVE-2026-93923, SiYuan through 3.8.4 fails to escape heading style attributes when rendering out...
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints t…
CVE-2026-93922, SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker...
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads i…
CVE-2026-84034, IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne...
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentia…
CVE-2026-82896, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
CVE-2026-82893, IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated ...
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
CVE-2026-82892, IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit...
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-82887, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-82885, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
CVE-2026-81937, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename …
CVE-2026-81933, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoin…
CVE-2026-81669, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias inpu…
CVE-2026-81656, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST end…
CVE-2026-81626, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potent…
CVE-2026-17619, IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp...
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-11727, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo...
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when re…
CVE-2026-11726, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
CVE-2026-11725, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
CVE-2026-11716, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster mi…
CVE-2017-20284, Caucho Resin contains a path traversal vulnerability in the documentation webapp...
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request…
CVE-2021-48008, Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows ...
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploi…
CVE-2019-25776, Weaver E-cology contains an unauthenticated SQL injection vulnerability that all...
Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile …
CVE-2026-93749, source-map-js through 1.2.1 fails to validate the per-section offset line value ...
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that…
CVE-2026-93559, A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0...
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manip…
CVE-2026-91149, A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this...
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to creat…
CVE-2026-93690, uri-js through 4.4.1 contains a denial of service vulnerability in the removeDot...
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by …
CVE-2026-93688, SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra...
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the…
CVE-2026-81942, PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bef...
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system…
CVE-2026-11378, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
CVE-2026-11375, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
CVE-2026-10853, IBM MQ could allow an authenticated attacker with cluster access to cause a deni...
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
CVE-2026-10751, IBM MQ Java and JMS client libraries could allow an authenticated attacker to ex...
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
CVE-2026-10575, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
CVE-2026-10027, IBM MQ could allow a remote attacker to cause a denial of service or execute arb...
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
CVE-2025-14753, IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directori...
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on th…
CVE-2026-93657, hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof sta...
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers …
CVE-2026-93576, Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomple...
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
CVE-2026-93569, HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overridin...
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
CVE-2026-93568, HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT re...
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
CVE-2026-93567, HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Hos...
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
CVE-2026-93565, ### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any...
### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the full range that `String.trim()` removes) before performing a cache lookup against its ten pre-popula…
CVE-2026-93564, HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete ...
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)
CVE-2026-93558, Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads t...
Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
CVE-2026-77929, ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows...
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint…