CVE ID :CVE-2026-91144 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago Description :ZFile through 5.0.5 fails to validate requested file paths against a share link’s allowed entries on the…
CVE-2026-12944 – Incomplete Security Scanner Blocklist Enables Network-Based Code Execution
CVE ID :CVE-2026-12944 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago Description :IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges…
CVE-2026-91200 – DevSpace through 6.3.21 Path Traversal via tar extraction
CVE ID :CVE-2026-91200 Published : Sept. 14, 2026, 10:10 p.m. | 1 hour, 7 minutes ago Description :DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream….
CVE-2026-90896 – Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII
CVE ID :CVE-2026-90896 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions,…
CVE-2026-68489 – Plesk Extensions Ruby and Node.js Toolkit Static Code Injection
CVE ID :CVE-2026-68489 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Static Code Injection in Plesk extensions “Ruby” before 1.6.6 and “Node.js Toolkit” before 2.5.0 allows remote authenticated…
CVE-2026-90606 – Totolink A3002MU boa formIpv6Setup buffer overflow
CVE ID :CVE-2026-90606 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the…
CVE-2026-90605 – Totolink A3002MU boa formFilter buffer overflow
CVE ID :CVE-2026-90605 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file…
CVE-2026-88793 – YouTube Embed 10.0 – 10.3 – Unauthenticated Stored XSS via youram_server
CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one…
CVE-2026-85129 – Hoo Companion 1.0.2 – Unauthenticated Stored XSS via Theme Settings Import
CVE ID :CVE-2026-85129 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of…
CVE-2026-81648 – CryptoPayment Gateway 1.2.1 – 1.2.2 – Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
CVE ID :CVE-2026-81648 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one…