Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-12224

Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint_CVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including...

wedevs Dokan Pro CVE
HIGH 8.8 CVE-2026-12158

RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter_CVE-2026-12158

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...

metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 6.0.9.1 CVE
CRITICAL 9.8 CVE-2026-11387

SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset_CVE-2026-11387

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation...

cozyvision1 SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 3.9.5 CVE
MEDIUM 5.6 CVE-2026-10540

Weak password hash protection in Control-M/Entreprise Manager_CVE-2026-10540

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attac...

BMC Control-M/Enterprise Manager 9.0.21 CVE
CRITICAL 9.5 CVE-2026-10539

Unauthenticated command injection in Control-M/Server communication command_CVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may all...

BMC Control-M/Server 9.0.21.300 CVE
HIGH 8.9 CVE-2026-10538

Improper deserialization handling in Control-M Components_CVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out o...

BMC Control-M/Enterprise Manager 9.0.21 CVE
MEDIUM 4.3 CVE-2026-10096

Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter_CVE-2026-10096

The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' ...

qodeinteractive Qi Blocks CVE
MEDIUM 6.9 MS:CVE-2026-41992

Global Buffer Overflow in GNU gzip_MS:CVE-2026-41992

{“lastseen”:”2026-07-01T07:54:17″,”description”:””,”published”:”2026-06-30T08:02:...

N/A N/A MSCVE
NONE THN:7E63B6C8578...

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls_THN:7E63B6C8578E5F08078423004F4C49C6

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2AmA92QCIqSJfXqC3z9I1jjdJGEkIvN4k-Oc5MlWZb4yZLPg5clokead6q8yXUfeI4DbdsKVn4qbd1sufvo...

N/A N/A THN
NONE THN:790F5359258...

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware_THN:790F5359258638A19E7DEA99AE4EA21A

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX2IWQhpupx-U0U70hWTg9afsBb41pslrGP733mXXdBKValODZrPoYD3UQqGVq1j9fSgmgf9rqDyxEAx1iKz...

N/A N/A THN