Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-12610

Sssd: use-after-free crash in sssd’ ‘sssd_pam’ process_CVE-2026-12610

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memor...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 4.4 CVE-2026-13316

Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config_CVE-2026-13316

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF a...

Red Hat Red Hat Satellite 6 CVE
MEDIUM 5.3 CVE-2026-12349

Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions_CVE-2026-12349

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and includi...

octagonwebstudio Premium Addons for KingComposer CVE
MEDIUM 6.5 CVE-2026-11367

PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter_CVE-2026-11367

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the...

andrasweb PixMagix – WordPress Image Editor CVE
MEDIUM 6.1 CVE-2026-56809

CVE-2026-56809_CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerab...

Ricoh Company, Ltd. Multiple laser printers and MFPs which implement Ricoh Web Image Monitor see the information provided by the vendor CVE
MEDIUM 6.6 CVE-2026-45822

CVE-2026-45822_CVE-2026-45822

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decod...

SamVerschueren decode-uri-component 0.1.0 CVE
MEDIUM 5.9 CVE-2026-14160

CVE-2026-14160_CVE-2026-14160

Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race Conditions. This issue affe...

Samsung Open Source Escargot bab3a5797557014ce3c2e28419a6310cfba90d0d CVE
MEDIUM 4.4 CVE-2026-12114

Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter_CVE-2026-12114

The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...

wpmart Team Members – Multi Language Supported Team Plugin CVE
MEDIUM 4.3 CVE-2026-8944

Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter_CVE-2026-8944

The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin...

engagementanalytics Plugin for Google Analytics by IO technologies CVE
MEDIUM 4.4 CVE-2026-12560

Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field_CVE-2026-12560

The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all...

wpqode Editorial Rating – Product Review & Rating System CVE