Vulnerability Notes
- CVE-2026-93962 - Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
- CVE-2026-86553 - A password reset vulnerability in ZTE SmartLife APP
- CVE-2026-93958 - D-Link R95 DHMAPI ssi system os command injection
- CVE-2026-93990 - Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate
- CVE-2026-93985 - OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
- CVE-2026-78030 - DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
- CVE-2026-93742 - Totolink A3002MU formWsc command injection
- CVE-2026-85658 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
- CVE-2026-4327 - The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter
- CVE-2026-86591 - Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route
- CVE-2026-85574 - Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains
- CVE-2026-93741 - Totolink A3002MU formWlWds buffer overflow
- CVE-2026-92229 - Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter
- CVE-2026-89274 - WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content
- CVE-2026-84434 - Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field