-Infinity
0

Templately – Elementor & Gutenberg Template Library for WordPressTemplately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch

Risk 79
Severity
8.8
First published (updated )

WordPress Real Estate Manager ProReal Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision

Risk 70
Severity
7.5
First published (updated )

CedCommerce Wholesale Market plugin for WordPressWholesale Market <= 2.2.2 - Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter

Risk 79
Severity
8.8
First published (updated )

WordPressCookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter

Risk 44
Severity
7.2
First published (updated )

WordPress Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All FormsInvisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter

Risk 44
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

bLoyal bLoyal: Loyalty & PromotionsbLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings

Risk 79
Severity
8.8
First published (updated )

WordPress Object Sync for SalesforceObject Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection

Risk 43
Severity
7.5
First published (updated )

MaxUpload Big File Uploads – Increase Maximum File Upload Size (WordPress plugin)MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter

Risk 79
Severity
8.8
First published (updated )

Propovoice Propovoice: All-in-One Client Management System plugin for WordPressPropovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter

Risk 79
Severity
8.8
First published (updated )

vcita Online Booking & Scheduling Calendar for WordPressOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter

Risk 44
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@ooples/token-optimizer-mcpOS Command Injection, Command Injection

Risk 74
Severity
8.4
First published (updated )

npm/@ooples/token-optimizer-mcpOS Command Injection, Command Injection

Risk 74
Severity
8.4
First published (updated )

Laravel Socialite Facebook ProviderLaravel Socialite Facebook Provider Authentication Bypass via Nonce Replay

Risk 75
Severity
8.1
First published (updated )

Semaphore SemaphoreSemaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling

Risk 79
Severity
8.8
First published (updated )

PAX Technology Q80 Application InstallerPAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

Risk 70
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PAX Technology Q80PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability

Risk 48
Severity
7.1
First published (updated )

PAX Technology Q80PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability

Risk 70
Severity
7.5
First published (updated )

Cockpit CMS Cockpit CMSCockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename

Risk 79
Severity
8.8
First published (updated )

maven/com.mchange:mchange-commons-java### Impact Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementati…

Risk 66
Severity
7.1
First published (updated )

go/github.com/lima-vm/lima/v2### Impact On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could acce…

Risk 64
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netatalk afpd daemonNetatalk has Integer Underflow → Stack Buffer Overflow in copydir()

Risk 72
Severity
7.5
First published (updated )

ImpressCMS ImpressCMSImpressCMS Authenticated RCE via PHP Custom Tag eval()

Risk 66
Severity
7.2
First published (updated )

Zephyr Project ZephyrUse-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal

Risk 72
Severity
8.8
First published (updated )

subsys/logging/log_msg.cMissing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service

Risk 59
Severity
8.4
First published (updated )

Security CenterSQL Injection

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Security Center Security CenterImproper Input Validation

Risk 79
Severity
8.8
First published (updated )

TOTOLINK A800RTOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow

Risk 78
Severity
8.8
First published (updated )

TOTOLINK A800RTOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow

Risk 78
Severity
8.8
First published (updated )

Security CenterLocal Privilege Escalation

Risk 72
Severity
8.8
First published (updated )

Tenable Tenable Security CenterPrivilege Escalation

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203