Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-12575

DVP80ES3 Improper Resource Shutdown or Release Vulnerability_CVE-2026-12575

DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.

deltaww DVP80ES3 CVE
HIGH 8.8 CVE-2026-12224

Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint_CVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including...

wedevs Dokan Pro CVE
HIGH 8.8 CVE-2026-12158

RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter_CVE-2026-12158

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...

metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 6.0.9.1 CVE
HIGH 8.9 CVE-2026-10538

Improper deserialization handling in Control-M Components_CVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out o...

BMC Control-M/Enterprise Manager 9.0.21 CVE
HIGH 7.5 CVE-2026-1239

Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint_CVE-2026-1239

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing a...

kstover Ninja Forms – The Contact Form Builder That Grows With You CVE
HIGH 7.5 CVE-2026-14193

DVP80ES300T – Improper Validation of Array Index Vulnerability_CVE-2026-14193

DVP80ES300T with Improper Validation of Array Index Vulnerability

deltaww DVP80ES300T CVE
HIGH 7.4 CVE-2026-12579

AS228T – Authentication Bypass Vulnerability_CVE-2026-12579

AS228T with Authentication Bypass Vulnerability

deltaww AS228T CVE
HIGH 7.5 CVE-2026-11823

BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter_CVE-2026-11823

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assi...

Repute Infosystems BookingPress Appointment Booking Pro CVE
HIGH 8.8 CVE-2026-7838

UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length_CVE-2026-7838

UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. I...

uvnc UltraVNC CVE
HIGH 7.5 CVE-2026-7831

UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing_CVE-2026-7831

UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.c...

uvnc UltraVNC CVE