-Infinity
0

ASUSTOR ASUSTOR Backup PlanAn improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.

Risk 57
First published (updated )

GeoVision GV-ASManagerGV-ASManager DLL hijacking vulnerability

Risk 64
Severity
7.3
First published (updated )

GV-AS1620 Controller FirmwareHardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)

Risk 66
Severity
9.1
First published (updated )

GV-AS1620 Controller FirmwareHardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager)

Risk 66
Severity
9.1
First published (updated )

CVE-2026-67243freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability.…

Risk 66
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Update SupportLow: php8.4 security, bug fix, and enhancement update

Risk 5
Severity
1
First published (updated )

Linux Kernel Organization Linux kernelInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()

Risk 80
First published (updated )

CVE-2026-64564sctp: don't free the ASCONF's own transport in DEL-IP processing

Risk 52
First published (updated )

Linux Linux kernelrhashtable: clear stale iter->p on table restart

Risk 37
First published (updated )

Linux KernelKVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Risk 44
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Linux Linux kernelKVM: nVMX: Hide shadow VMCS right after VMCLEAR

Risk 31
First published (updated )

Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updatesImportant: fence-agents security update

Risk 33
Severity
7
First published (updated )

WordPress pluginBit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint

Risk 22
First published (updated )

WordPress REST API LogREST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint

Risk 71
First published (updated )

Brizy Brizy - Page BuilderBrizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point

Risk 43
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WordPress plugin Clearfy CacheClearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler

Risk 20
First published (updated )

Wired Impact Volunteer Management WordPress pluginWired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp

Risk 45
First published (updated )

Blubrry PowerPress Podcasting pluginBlubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL

Risk 37
First published (updated )

WordPress plugin Clearfy CacheClearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher

Risk 48
First published (updated )

Brizy Brizy - Page BuilderBrizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR

Risk 36
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Brizy - Page BuilderBrizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset

Risk 53
First published (updated )

WordPress Contest GalleryContest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts

Risk 48
First published (updated )

WordPress plugin "Easy Dropbox Integration"Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX

Risk 84
First published (updated )

miniOrange 2FA WordPress pluginminiOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send

Risk 38
First published (updated )

WordPress plugin "Contact Form 7"Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter

Risk 50
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Visualizer Visualizer: Tables and Charts ManagerVisualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import

Risk 73
First published (updated )

WordPress Nested PagesNested Pages < 3.2.15 - Editor+ Stored XSS via Post Title

Risk 45
First published (updated )

Paid Membership SubscriptionsPaid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout

Risk 57
First published (updated )

WordPress Quiz And Survey Master (QSM) pluginQuiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question

Risk 40
First published (updated )

EmbedPress EmbedPress WordPress pluginEmbedPress < 4.6.1 - Unauthenticated Blind SSRF

Risk 62
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203