Aggregator
CVE-2026-34905 | Apache Answer up to 2.0.0 API information disclosure
3 days 20 hours ago
A vulnerability was found in Apache Answer up to 2.0.0 and classified as problematic. This issue affects some unknown processing of the component API. The manipulation results in information disclosure.
This vulnerability is known as CVE-2026-34905. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-34033 | hapijs content up to 2.0.0 Email cross site scripting
3 days 20 hours ago
A vulnerability has been found in hapijs content up to 2.0.0 and classified as problematic. This vulnerability affects unknown code of the component Email Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-34033. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-34031 | Apache Answer up to 2.0.0 Custom Avatar unrestricted upload
3 days 20 hours ago
A vulnerability, which was classified as critical, was found in Apache Answer up to 2.0.0. This affects an unknown part of the component Custom Avatar Handler. Executing a manipulation can lead to unrestricted upload.
This vulnerability appears as CVE-2026-34031. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-33582 | Apache Answer up to 2.0.0 TIFF File unrestricted upload
3 days 20 hours ago
A vulnerability, which was classified as critical, has been found in Apache Answer up to 2.0.0. Affected by this issue is some unknown functionality of the component TIFF File Handler. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2026-33582. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-25699 | Apache Answer up to 2.0.0 Timeline API authorization
3 days 20 hours ago
A vulnerability classified as problematic was found in Apache Answer up to 2.0.0. Affected by this vulnerability is an unknown functionality of the component Timeline API. Such manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-25699. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-25688 | Apache Answer up to 2.0.0 AI Answer Rendering cross site scripting
3 days 20 hours ago
A vulnerability classified as problematic has been found in Apache Answer up to 2.0.0. Affected is an unknown function of the component AI Answer Rendering. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-25688. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
AI 泡沫里的硅谷:清醒的赌徒,与疯狂加倍的牌桌
3 days 20 hours ago
比AI泡沫更值得关注的,是泡沫里的人。
CVE-2026-41980 | Huawei HarmonyOS 6.0.0/6.1.0 File Preview information disclosure
3 days 20 hours ago
A vulnerability described as problematic has been identified in Huawei HarmonyOS 6.0.0/6.1.0. This impacts an unknown function of the component File Preview Module. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-41980. The attack must be initiated from a local position. There is no exploit available.
vuldb.com
CVE-2026-41979 | Huawei HarmonyOS 6.0.0/6.1.0 Print
3 days 20 hours ago
A vulnerability marked as problematic has been reported in Huawei HarmonyOS 6.0.0/6.1.0. This affects an unknown function of the component Print Module. The manipulation leads to an unknown weakness.
This vulnerability is listed as CVE-2026-41979. The attack must be carried out locally. There is no available exploit.
vuldb.com
CVE-2026-41978 | Huawei HarmonyOS 6.0.0/6.1.0 Clone permission
3 days 20 hours ago
A vulnerability labeled as critical has been found in Huawei HarmonyOS 6.0.0/6.1.0. The impacted element is an unknown function of the component Clone Module. Executing a manipulation can lead to permission issues.
This vulnerability is tracked as CVE-2026-41978. The attack is restricted to local execution. No exploit exists.
vuldb.com
CVE-2026-41975 | Huawei HarmonyOS 6.0.0/6.1.0 Network Management permission
3 days 20 hours ago
A vulnerability identified as critical has been detected in Huawei HarmonyOS 6.0.0/6.1.0. The affected element is an unknown function of the component Network Management Module. Performing a manipulation results in permission issues.
This vulnerability is identified as CVE-2026-41975. The attack is only possible with local access. There is not any exploit available.
vuldb.com
CVE-2026-10553 | weaverlancegmailcom jQuery Hover Footnotes Plugin up to 1.4 on WordPress Setting update_option cross-site request forgery
3 days 20 hours ago
A vulnerability categorized as problematic has been discovered in weaverlancegmailcom jQuery Hover Footnotes Plugin up to 1.4 on WordPress. Impacted is the function update_option of the component Setting Handler. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-10553. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-8883 | helpstring Global Body Mass Index Calculator Plugin up to 1.2 on WordPress Shortcode GBMI_Calc_Widget::widget args cross site scripting (EUVD-2026-35299)
3 days 20 hours ago
A vulnerability was found in helpstring Global Body Mass Index Calculator Plugin up to 1.2 on WordPress. It has been rated as problematic. This issue affects the function GBMI_Calc_Widget::widget of the component Shortcode Handler. This manipulation of the argument args causes cross site scripting.
The identification of this vulnerability is CVE-2026-8883. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-9185 | sixstorage 6Storage Rentals Plugin up to 2.22.0 on WordPress Request six_storage_getUserInfo userId authorization (EUVD-2026-35307)
3 days 20 hours ago
A vulnerability was found in sixstorage 6Storage Rentals Plugin up to 2.22.0 on WordPress. It has been declared as problematic. This vulnerability affects the function six_storage_getUserInfo of the component Request Handler. The manipulation of the argument userId results in authorization bypass.
This vulnerability was named CVE-2026-9185. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8977 | techjewel WP GDPR Cookie Consent Plugin up to 1.0.0 on WordPress Configuration handleAjaxCalls gdprConfig cross site scripting
3 days 20 hours ago
A vulnerability was found in techjewel WP GDPR Cookie Consent Plugin up to 1.0.0 on WordPress. It has been classified as problematic. This affects the function handleAjaxCalls of the component Configuration Handler. The manipulation of the argument gdprConfig leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-8977. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-8910 | rahulbhangale WP Emoticon Rating Plugin up to 1.0.1 on WordPress Setting cross-site request forgery
3 days 20 hours ago
A vulnerability was found in rahulbhangale WP Emoticon Rating Plugin up to 1.0.1 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is handled as CVE-2026-8910. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-8909 | rahulbhangale WpMobi Plugin up to 0.0.3 on WordPress Setting handleSaveGeneralSettings app_name cross-site request forgery (EUVD-2026-35306)
3 days 20 hours ago
A vulnerability has been found in rahulbhangale WpMobi Plugin up to 0.0.3 on WordPress and classified as problematic. Affected by this vulnerability is the function handleSaveGeneralSettings of the component Setting Handler. Performing a manipulation of the argument app_name results in cross-site request forgery.
This vulnerability is known as CVE-2026-8909. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-8907 | rahulbhangale WP-Ultimate-Map Plugin up to 1.1 on WordPress Setting process_init save-setting cross-site request forgery (EUVD-2026-35304)
3 days 20 hours ago
A vulnerability, which was classified as problematic, was found in rahulbhangale WP-Ultimate-Map Plugin up to 1.1 on WordPress. Affected is the function process_init of the component Setting Handler. Such manipulation of the argument save-setting leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-8907. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8902 | tierrainnovation AJAX Report Comments Plugin up to 2.0.4 on WordPress Setting already-reported rc_options_page cross-site request forgery (EUVD-2026-35308)
3 days 20 hours ago
A vulnerability, which was classified as problematic, has been found in tierrainnovation AJAX Report Comments Plugin up to 2.0.4 on WordPress. This impacts the function rc_options_page of the file /failure/already-reported of the component Setting Handler. This manipulation causes cross-site request forgery.
This vulnerability appears as CVE-2026-8902. The attack may be initiated remotely. There is no available exploit.
vuldb.com