A vulnerability classified as critical was found in jegstudio Gutenverse Plugin up to 3.5.3 on WordPress. This affects the function import_images. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-2948. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in ahmadgb GeekyBot Plugin up to 1.2.2 on WordPress and classified as critical. This vulnerability affects unknown code of the component ZIP File Handler. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-5294. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
A vulnerability, which was classified as problematic, was found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress. This issue affects the function wpr_update_form_action_meta of the component AJAX Handler. Executing a manipulation of the argument Status can lead to cross site scripting.
This vulnerability is registered as CVE-2026-4803. It is possible to launch the attack remotely. No exploit is available.
A vulnerability has been found in roxnor EmailKit Plugin up to 1.6.5 on WordPress and classified as critical. This affects the function create_template of the file wp-content/uploads/emailkit/templates/. Performing a manipulation of the argument real_path results in path traversal.
This vulnerability is reported as CVE-2026-5957. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, has been found in shapedplugin WP Carousel Free Plugin up to 2.7.10 on WordPress. This vulnerability affects the function wp_kses_post of the file fancybox-config.js of the component Fancybox Handler. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-4665. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-7810. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability has been found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress and classified as problematic. Impacted is the function instagram_follow_text of the component Instagram Feed Widget. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-5159. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in roxnor ElementsKit Elementor Addons Plugin up to 3.8.2 on WordPress. It has been rated as critical. Affected by this issue is the function Live_Action::reset. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-4362. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in io.quarkus:quarkus-vertx-http. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/admin of the component HTTP Request Handler. Executing a manipulation can lead to authorization bypass.
This vulnerability appears as CVE-2026-39852. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in argoproj argo-workflows. It has been classified as critical. Affected is an unknown function of the component Sync ConfigMap Provider. Performing a manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-42297. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in argoproj argo-workflows and classified as problematic. This impacts an unknown function of the component Artifact Repository Credential Handler. Such manipulation leads to insufficiently protected credentials.
This vulnerability is documented as CVE-2026-42295. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Pillow and classified as problematic. This affects an unknown function of the component PSD Tile Extents Handler. This manipulation causes integer overflow.
This vulnerability is registered as CVE-2026-42311. The attack needs to be launched locally. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in chainguard-dev apko 0.14.5/1.1.0/1.1.1. The impacted element is the function dirFS of the file pkg/apk/fs/rwosfs.go. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-42574. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Apache Thrift up to 0.22.x. The affected element is an unknown function of the file web_server.js. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2026-43870. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Apache Thrift up to 0.22.x. Impacted is an unknown function of the file TSSLTransportFactory.java. Executing a manipulation can lead to certificate with host mismatch.
This vulnerability is tracked as CVE-2026-43869. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Apache Thrift up to 0.22.x. This issue affects some unknown processing of the component Rust. Performing a manipulation results in privilege escalation.
This vulnerability is identified as CVE-2026-43868. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in kazunii addfreespace Plugin up to 0.1.3 on WordPress. This vulnerability affects unknown code of the component Setting Handler. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-6701. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as problematic has been reported in phpsandeepkumar Blog Settings Plugin up to 1.0 on WordPress. This affects an unknown part of the component Setting Handler. This manipulation of the argument page causes cross site scripting.
The identification of this vulnerability is CVE-2026-6704. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in foux Publish 2 Ping.fm Plugin up to 1.1 on WordPress. Affected by this issue is some unknown functionality of the file /wp-admin/options-general.php?page=admin.php of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability was named CVE-2026-6702. The attack may be performed from remote. There is no available exploit.