Aggregator
CVE-2026-10583 | nextlevelbuilder GoClaw up to 3.11.3 TTS Configuration Endpoint tts_config.go import server-side request forgery (Issue 1132)
2 weeks 1 day ago
A vulnerability classified as critical has been found in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-10583. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project tagged the reported issue as bug.
vuldb.com
Submit #829407: nextlevelbuilder GoClaw <= 3.11.3 Server-Side Request Forgery (SSRF) (CWE-918) [Accepted]
2 weeks 1 day ago
Submit #829407 / VDB-367710
Eric-b
Dashlane password manager users locked out by brute force attacks
2 weeks 1 day ago
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. [...]
Bill Toulas
CVE-2026-42676 | myCred Plugin up to 3.0.4 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability described as problematic has been identified in myCred Plugin up to 3.0.4 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-42676. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-42674 | AAM Plugin Advanced Access Manager Plugin up to 7.1.0 on WordPress authentication spoofing
2 weeks 1 day ago
A vulnerability marked as critical has been reported in AAM Plugin Advanced Access Manager Plugin up to 7.1.0 on WordPress. Affected is an unknown function. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability is reported as CVE-2026-42674. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-42678 | Liquid Web/StellarWP GiveWP Plugin up to 4.14.5 on WordPress cross site scripting
2 weeks 1 day ago
A vulnerability labeled as problematic has been found in Liquid Web/StellarWP GiveWP Plugin up to 4.14.5 on WordPress. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-42678. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-45153 | Nextcloud Android Files 33.0.x improper authentication (GHSA-2w7v-5299-3hw5)
2 weeks 1 day ago
A vulnerability identified as critical has been detected in Nextcloud Android Files 33.0.x. This affects an unknown function. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2026-45153. It is feasible to perform the attack on the physical device. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8501 | Symantec PC Tools Internet Security 64.sys PCTCoreDriver WDM Device Interface PCTCore64.sys exposed ioctl with insufficient access control
2 weeks 1 day ago
A vulnerability categorized as critical has been discovered in Symantec PC Tools Internet Security 64.sys. The impacted element is an unknown function in the library PCTCore64.sys of the component PCTCoreDriver WDM Device Interface. The manipulation results in exposed ioctl with insufficient access control.
This vulnerability is cataloged as CVE-2026-8501. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-44211 | Cline up to 2.13.0 missing authentication (GHSA-5c57-rqjx-35g2)
2 weeks 1 day ago
A vulnerability was found in Cline up to 2.13.0. It has been rated as critical. The affected element is an unknown function. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-44211. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-42677 | Ben Balter WP Document Revisions Plugin up to 3.x on WordPress authorization
2 weeks 1 day ago
A vulnerability was found in Ben Balter WP Document Revisions Plugin up to 3.x on WordPress. It has been declared as problematic. Impacted is an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-42677. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42675 | Themefic Hydra Booking Plugin up to 1.1.41 on WordPress authorization
2 weeks 1 day ago
A vulnerability was found in Themefic Hydra Booking Plugin up to 1.1.41 on WordPress. It has been classified as critical. This issue affects some unknown processing. Performing a manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-42675. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-42673 | Logtivity Activity Logs, User Activity Tracking, Multisite Activity Log Plugin insertion of sensitive information into sent data
2 weeks 1 day ago
A vulnerability was found in Logtivity Activity Logs, User Activity Tracking, Multisite Activity Log Plugin up to 3.3.6 on WordPress and classified as problematic. This vulnerability affects unknown code. Such manipulation leads to insertion of sensitive information into sent data.
This vulnerability is referenced as CVE-2026-42673. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-42672 | WP Directory Kit Plugin up to 1.5.1 on WordPress sql injection
2 weeks 1 day ago
A vulnerability has been found in WP Directory Kit Plugin up to 1.5.1 on WordPress and classified as critical. This affects an unknown part. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2026-42672. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-42671 | Paolo GeoDirectory Plugin up to 2.8.157 on WordPress authorization
2 weeks 1 day ago
A vulnerability, which was classified as critical, was found in Paolo GeoDirectory Plugin up to 2.8.157 on WordPress. Affected by this issue is some unknown functionality. The manipulation results in missing authorization.
This vulnerability was named CVE-2026-42671. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-38950 | ESA AnomalyMatch up to 1.3.0 Model torch.load deserialization
2 weeks 1 day ago
A vulnerability, which was classified as problematic, has been found in ESA AnomalyMatch up to 1.3.0. Affected by this vulnerability is the function torch.load of the component Model Handler. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-38950. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-45267 | Nextcloud Forms up to 5.2.5 information disclosure (GHSA-r4gh-f8x6-m55f)
2 weeks 1 day ago
A vulnerability classified as problematic was found in Nextcloud Forms up to 5.2.5. Affected is an unknown function. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2026-45267. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45266 | Nextcloud Talk up to 21.1.9/22.0.10/23.0.2 access control (GHSA-x75r-65hm-cw35)
2 weeks 1 day ago
A vulnerability classified as critical has been found in Nextcloud Talk up to 21.1.9/22.0.10/23.0.2. This impacts an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is known as CVE-2026-45266. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-45264 | Nextcloud Team Folders up to 21.0.3 access control (GHSA-wx2x-822r-rvmf)
2 weeks 1 day ago
A vulnerability described as critical has been identified in Nextcloud Team Folders up to 17.0.14/18.1.11/19.1.15/20.1.10/21.0.3. This affects an unknown function. Such manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-45264. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-45159 | Nextcloud End-to-End Encryption up to 1.15.3/1.16.2/1.17.0/1.18.0 authorization (GHSA-p3qw-7gwx-wg24)
2 weeks 1 day ago
A vulnerability marked as problematic has been reported in Nextcloud End-to-End Encryption up to 1.15.3/1.16.2/1.17.0/1.18.0. The impacted element is an unknown function. This manipulation causes authorization bypass.
This vulnerability appears as CVE-2026-45159. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com