Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-47339

Apache APISIX: authz-casdoor incorrect session sharing_CVE-2026-47339

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenti...

Apache Software Foundation Apache APISIX 2.14.1 CVE
MEDIUM 5.3 CVE-2026-44087

Apache APISIX: Openid-connect plugin Identity Header Spoofing_CVE-2026-44087

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack...

Apache Software Foundation Apache APISIX 2.3 CVE
MEDIUM 5.8 CVE-2026-39998

Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup_CVE-2026-39998

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof...

Apache Software Foundation Apache APISIX 2.12.0 CVE
MEDIUM 6.3 CVE-2026-21768

HCL Verse for Android is susceptible to an injection vulnerability_CVE-2026-21768

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input...

HCLSoftware Verse for Android 14.5.10 CVE
MEDIUM 4.3 A421CF0C-0048-

Exploit for CVE-2026-11784_A421CF0C-0048-58EE-A8C4-F3EBF49171F1

CVE-2026-11784: CSRF to Arbitrary File Overwrite in Optimole WordPress Plugin Summary A Cross-Site Request Forgery CSRF vulnerability in the Optimo...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.3 CVE-2026-8049

CVE-2026-8049_CVE-2026-8049

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEV...

SignalRGB SignalRGB kernel driver CVE
MEDIUM 4.3 CVE-2026-9199

Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' Parameter_CVE-2026-9199

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass i...

equalizedigital Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance CVE
MEDIUM 5.3 CVE-2026-12120

FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Parameter_CVE-2026-12120

The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u...

fireplugins FireBox Popups – Increase Sales and Grow Your Email List CVE
MEDIUM 5.3 CVE-2026-12093

Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook_CVE-2026-12093

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the pl...

wpinsider-1 Simple Membership CVE
MEDIUM 4.3 CVE-2026-11784

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action_CVE-2026-11784

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Reques...

optimole Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization CVE