Latest Security Vulnerabilities
Sunday September 20, 2026
Zte
CVE-2026-86551 Z80Ultra (NX741J) Android: WiFi MAC Address DisclosureCVE-2026-86554 SmartLife App Auth Param Leak Enables Account Enumeration
CVE-2026-86552 Authentication Bypass in SmartLife App via Unverified Email Sign-Up
CVE-2026-86555 Hardcoded Key in ZTE SmartLife App Exposes Server Info
CVE-2026-86553 SmartLife Auth Param Leak Allows Password Reset
Unclassified
CVE-2026-82842 WordPress SAML Single Sign On <6.0.0 Identity Link BypassCVE-2026-84223 Kirki <6.3.1 WP plugin unsanitized SVG upload risk
CVE-2026-81654 Photo Gallery, Sliders WP Plugin <4.5.0 Improper Capability Check
CVE-2026-81651 Gallery Ownership Bypass in Photo Gallery, Sliders, Proofing & Themes v<4.5.0
CVE-2026-85017 Arbitrary PHP Object Injection in Unlimited Elements For Elementor <=2.0.19
CVE-2026-87067 Forminator Forms <1.57.2.1 RCE via XML-RPC Deserialization
CVE-2026-87068 Forminator Forms <=1.57.2.1 Role Validation Bypass via Nested Quiz
CVE-2026-87839 Tripzzy WP Plugin < 1.5.1: Unauth AJAX Allows Comment Deletion
CVE-2026-92423 Meow Gallery <5.5.5: Missing Capability Check Exposes Draft Post Metadata
And others...
Oisf Suricata
CVE-2026-94083 Suricata <8.0.7 DoH2 type confusion leads to invalid freeCVE-2026-94084 Suricata <8.0.7 Http2ThreadMultiBuf use-after-free
CVE-2026-57223 Suricata <7.0.17 / <8.0.6 Windows Service LPE via Unquoted ImagePath
CVE-2026-57228 Suricata <7.0.17 Heap OOB Read in SMTP MIME Decoder
Getid3
CVE-2026-94106 getID3 <1.9.26 OS Command Injection via Unescaped FilenamesCVE-2026-94108 getID31.9.26 XXE via XML2array (PHP<8.0)
Sourcecodester Online Reviewer Management System
CVE-2026-93959 SQLi via Course param in btn_functions.php of SCM System 1.0CVE-2026-93972 SQL Injection in SourceCodester Online Reviewer Mgmt 1.0 via btn_functions.php
CVE-2026-93973 SourceCodester Online Reviewer Mgmt Sys 1.0 SQLi via btn_functions.php
CVE-2026-93974 SQLi via btn_functions.php in SourceCodester Online Reviewer System 1.0
Aiyiyi121 Sxdevops
CVE-2026-93965 Command Injection in aiyiyi121 SxDevOps 1.0/1.1 MCP STDIO Server MgmtCVE-2026-93966 Command Injection in aiyiyi121 SxDevOps 1.0/1.1 via TASK_RUN exec_command
CVE-2026-93967 Command Handler in Aiyiyi121 SxDevOps 1.1: CMD Injection in generate_host_task
CVE-2026-93968 SxDevOps 1.0/1.1 Privilege Escalation via UserSerializer update
CVE-2026-93969 Hard-Coded Credentials in aiiyi121 SxDevOps 1.01.1 rbac/services.py
CVE-2026-93970 CVE-2026-93970: Hard-coded creds in aiyiyi121 SxDevOps 1.0 Settings Handler
CVE-2026-93971 aiyi yi121 SxDevOps 1.0/1.1 Remote Info Disclosure via settings.py
Code Projects Internship Management System
CVE-2026-93978 CVE-2026-93978: SQLi via /login.php Password in code-projects IMS 1.0CVE-2026-93979 SQL Injection in code-projects Internship Management System 1.0 /employer/login.php
CVE-2026-93980 Internship Mgmt Sys 1.0: SQLi via Password in /admin/login.php
Saturday September 19, 2026
Mischiefmarmot
CVE-2026-13200 WordPress Create Plugin <2.5.3 SQLi via order paramCVE-2026-13191 WordPress Create Plugin v2.5.3 SQLi via order_by Author+
Themeum Tutor Lms
CVE-2026-88944 TutorLMS WP Plugin Auth Bypass v4.0.8 enables post deletionCVE-2026-89081 Tutor LMS <4.0.8 Reflected XSS via search param
CVE-2026-89333 IDOR in Tutor LMS <=4.0.8 via student_id
Unclassified
CVE-2026-82842 WordPress SAML Single Sign On <6.0.0 Identity Link BypassCVE-2026-84223 Kirki <6.3.1 WP plugin unsanitized SVG upload risk
CVE-2026-81654 Photo Gallery, Sliders WP Plugin <4.5.0 Improper Capability Check
CVE-2026-81651 Gallery Ownership Bypass in Photo Gallery, Sliders, Proofing & Themes v<4.5.0
CVE-2026-85017 Arbitrary PHP Object Injection in Unlimited Elements For Elementor <=2.0.19
CVE-2026-87067 Forminator Forms <1.57.2.1 RCE via XML-RPC Deserialization
CVE-2026-87068 Forminator Forms <=1.57.2.1 Role Validation Bypass via Nested Quiz
CVE-2026-87839 Tripzzy WP Plugin < 1.5.1: Unauth AJAX Allows Comment Deletion
CVE-2026-92423 Meow Gallery <5.5.5: Missing Capability Check Exposes Draft Post Metadata
And others...
Exim
CVE-2026-94057 Exim <4.100.1 SMTP Smuggling via DATA RejectionCVE-2026-94056 Exim <4.100.1: Proxy-Protocol Uninit Stack Data Leak
CVE-2026-94055 Exim <4.100.1 Use-After-Free via GnuTLS TLS Settings
CVE-2026-94054 Exim <4.100.1 OOB Write via Proxy-Protocol (attacker-controlled IP)
Openpanel
CVE-2026-93982 OpenPanel logs unredacted MCP tokens from query parametersCVE-2026-93983 OpenPanel ClickHouse SQL Injection via Unsanitized Property Keys
CVE-2026-93984 OpenPanel Tracking API: Client Secret Hash Bypass Enables Revenue Injection
CVE-2026-93985 OpenPanel js-runtime Sandbox Escape via Webhook Template Validator
Friday September 18, 2026
IBM Guardium Data Protection
CVE-2026-84073 IBM Guardium 12.2 SQL Injection via Improper Neutralization of Special ElementsCVE-2026-84084 CVE-2026-84084: IBM Guardium Data Protection 12.2 CSRF allows remote bypass
CVE-2026-82832 Remote Code Exec in IBM Guardium DP 12.2 via Improper Input Neutralization
Unclassified
CVE-2026-82842 WordPress SAML Single Sign On <6.0.0 Identity Link BypassCVE-2026-84223 Kirki <6.3.1 WP plugin unsanitized SVG upload risk
CVE-2026-81654 Photo Gallery, Sliders WP Plugin <4.5.0 Improper Capability Check
CVE-2026-81651 Gallery Ownership Bypass in Photo Gallery, Sliders, Proofing & Themes v<4.5.0
CVE-2026-85017 Arbitrary PHP Object Injection in Unlimited Elements For Elementor <=2.0.19
CVE-2026-87067 Forminator Forms <1.57.2.1 RCE via XML-RPC Deserialization
CVE-2026-87068 Forminator Forms <=1.57.2.1 Role Validation Bypass via Nested Quiz
CVE-2026-87839 Tripzzy WP Plugin < 1.5.1: Unauth AJAX Allows Comment Deletion
CVE-2026-92423 Meow Gallery <5.5.5: Missing Capability Check Exposes Draft Post Metadata
And others...
ImageMagick
CVE-2026-93586 ImageMagick 7.1.2-31 UAF in ImagesToBlobCVE-2026-93588 ImageMagick <7.1.2-31 or <6.9.13-56 NULL Deref DoS in PNM Coder
MongoDB
CVE-2026-93763 MongoDB ODM FLE Config Failure Exposes CleartextCVE-2026-93764 Mongoid: Embedded Model Field Encryption Bypass (CVE-2026-93764)
IBM Cics Tx Advanced
CVE-2026-11549 IBM WAS Lib Virt. Host BypassCVE-2026-11722 HTTP Request Smuggling in IBM WebSphere Application Server
Synology Diskstation Manager
CVE-2026-13639 Low Entropy in DSM Login (<7.2.1-69057-12) Enables Remote File Access & DoSCVE-2026-4036 Synology DSM pre-7.3.2 SQLi via Sharing API remote auth
CVE-2026-6205 Synology DSM External Control of File Path Vulnerability before 7.2.1-69057-12
CVE-2026-40538 Synology DSM <7.2.2: Brute-Force Auth Allows Limited File Read
CVE-2026-40535 DSM Desktop API Path Traversal (7.2.1) Remote File Write
CVE-2026-40534 Synology DSM XSS in Video API before 7.3.2-86009-2
CVE-2026-40532 Forced Browsing in Wallpaper Path (DSM 7.x<7.2.1) Enables Auth Leak
Oisf Suricata
CVE-2026-94083 Suricata <8.0.7 DoH2 type confusion leads to invalid freeCVE-2026-94084 Suricata <8.0.7 Http2ThreadMultiBuf use-after-free
CVE-2026-57223 Suricata <7.0.17 / <8.0.6 Windows Service LPE via Unquoted ImagePath
CVE-2026-57228 Suricata <7.0.17 Heap OOB Read in SMTP MIME Decoder


