Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-55738

Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name field_CVE-2026-55738

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name...

rxi microtar 0.1.0 CVE
HIGH 8.5 CVE-2026-54818

WordPress Slimstat Analytics plugin <= 5.4.11 - SQL Injection vulnerability_CVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQ...

VeronaLabs Slimstat Analytics n/a CVE
HIGH 7.5 CVE-2026-54816

WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnerability_CVE-2026-54816

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affe...

Monetizemore Advanced Ads n/a CVE
HIGH 8.1 CVE-2026-54814

WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability_CVE-2026-54814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allo...

StylemixThemes Motors n/a CVE
HIGH 8.5 CVE-2026-54813

WordPress SureDash plugin <= 1.8.0 - SQL Injection vulnerability_CVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL In...

Brainstorm Force SureDash n/a CVE
HIGH 7.5 CVE-2026-54417

Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS_CVE-2026-54417

An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (unco...

rxi microtar 0.1.0 CVE
HIGH 7.7 CVE-2026-54193

WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability_CVE-2026-54193

Contributor Arbitrary File Deletion in Fusion Builder

ThemeFusion Fusion Builder n/a CVE
HIGH 8.1 CVE-2026-52707

WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability_CVE-2026-52707

Unauthenticated Local File Inclusion in Kastell

Mikado-Themes Kastell n/a CVE
HIGH 8.8 CVE-2026-49268

Apache Shiro: LDAP DN Injection in DefaultLdapRealm_CVE-2026-49268

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied usernam...

Apache Software Foundation Apache Shiro CVE
HIGH 8.1 CVE-2026-40757

WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability_CVE-2026-40757

Unauthenticated PHP Object Injection in Château

Mikado-Themes Château n/a CVE