Vulnerability Notes
- CVE-2026-103355 - WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability
- CVE-2026-105134 - Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection
- CVE-2026-88779 - Memory overflow vulnerability leading to Denial of Service
- CVE-2026-105126 - LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
- CVE-2026-105123 - W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
- CVE-2026-96451 - WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
- CVE-2026-103065 - WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability
- CVE-2026-105115 - OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
- CVE-2026-105105 - Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration
- CVE-2026-85515 - OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
- CVE-2026-71887 - OpenPGP data signature accepted from a signing subkey without cross-certification
- CVE-2026-71883 - Native AES packet cipher returns the raw AES key on an alias
- CVE-2026-92084 - Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output
- CVE-2026-94505 - Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter
- CVE-2026-87115 - VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter
- CVE-2026-18443 - Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter
- CVE-2026-88783 - Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content