Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment Clear
ID Title Severity CVSS Source Updated
cve-2026-94422 cve-2026-94422 UNKNOWN cvelistv5 unknown
cve-2025-64699 An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to perform unauthorized raw disk operations, which could lead to system disruption (DoS) and exposure of sensitive data, and may facilitate local privilege escalation. HIGH 7.8 cvelistv5 2026-09-23
cve-2025-62751 WordPress Vireo theme <= 1.0.24 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-62747 WordPress Featured Image Generator plugin <= 1.3.4 - Broken Access Control vulnerability MEDIUM 5.3 cvelistv5 2026-09-23
cve-2025-62154 WordPress AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin <= 1.1.7 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-62150 WordPress History Timeline plugin <= 1.0.6 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-62143 WordPress Post Video Players plugin <= 1.163 - Sensitive Data Exposure vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-62122 WordPress Trash Duplicate and 301 Redirect plugin <= 1.9.1 - Broken Access Control vulnerability MEDIUM 5.3 cvelistv5 2026-09-23
cve-2025-62116 WordPress AI Copilot plugin <= 1.5.2 - Broken Access Control vulnerability MEDIUM 5.3 cvelistv5 2026-09-23
cve-2025-62115 WordPress Hide Plugins plugin <= 1.0.4 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-62088 WordPress WordPress & WooCommerce Scraper plugin, Import Data from Any Site plugin <= 1.0.7 - Server Side Request Forgery (SSRF) vulnerability MEDIUM 5.4 cvelistv5 2026-09-23
cve-2025-62087 WordPress Sticky Notes for WP Dashboard plugin <= 1.2.4 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-49352 WordPress Order Cancellation & Returns for WooCommerce plugin <= 1.1.10 - Insecure Direct Object References (IDOR) vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-49340 WordPress Direct Payments WP plugin <= 1.3.2 - Sensitive Data Exposure vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2025-49339 WordPress Direct Payments WP plugin <= 1.3.2 - Broken Access Control vulnerability MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-88832 Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow HIGH 7.3 cvelistv5 2026-09-23
cve-2026-88830 Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow HIGH 7.5 cvelistv5 2026-09-23
cve-2026-96804 CVE-2026-96804 UNKNOWN cvelistv5 2026-09-23
cve-2026-96808 In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session could obtain two revokefs sessions via the system helper, create a symlink in one session pointing into the other session's directory, and retain a file descriptor through that symlink. This allowed the attacker to modify files belonging to a different revokefs session after they had been validated and imported by the system helper. In particular, an attacker could use this to tamper with ostree commit objects in the system repository after they passed signature verification, enabling root-controlled file writes to attacker-chosen paths and local root privilege escalation. HIGH 7.4 cvelistv5 2026-09-23
cve-2026-96807 In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit. MEDIUM 4.0 cvelistv5 2026-09-23
cve-2026-95847 Moquette client IDs can cause cross-session H2 durable-queue corruption HIGH 8.8 cvelistv5 2026-09-23
cve-2026-95842 Moquette uncaught MQTT command exceptions can terminate shared session event loops HIGH 8.7 cvelistv5 2026-09-23
cve-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection CRITICAL 9.3 cvelistv5 2026-09-23
cve-2026-96655 Plex Media Server arbitrary-host SSRF MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-96654 Plex Media Server URL injection MEDIUM 6.9 cvelistv5 2026-09-23
cve-2026-96652 Plex Media Server SSRF MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-96651 Plex Media Server path traversal MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-6669 Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer MEDIUM 5.9 cvelistv5 2026-09-23
cve-2026-6668 Integer overflow causes an infinite loop in packet buffer growth in PgBouncer HIGH 7.5 cvelistv5 2026-09-23
cve-2026-19888 NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer HIGH 7.5 cvelistv5 2026-09-23