Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-8039

Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting_CVE-2026-8039

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' ...

dijitul Fancy Testimonials CVE
MEDIUM 5.1 CVE-2026-50643

Out‑of‑Bounds Read in 8cc_CVE-2026-50643

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controll...

rui314 8cc b480958 CVE
MEDIUM 6.4 CVE-2026-2021

Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute_CVE-2026-2021

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versio...

contrid Slideshow Gallery LITE CVE
CRITICAL 9.3 CVE-2025-10560

Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources_CVE-2025-10560

Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries...

Silver Leaf Technologies, Inc. Worksnaps.net Worksnaps Worksnaps before 1.6.20260201 CVE
CRITICAL 9.3 CVE-2026-8024

Deserialization vulnerability in ibaPDA and ibaDatCoordinator_CVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access...

iba ibaPDA 1.0.0 CVE
MEDIUM 5.9 CVE-2026-56007

WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56007

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored X...

OceanWP Ocean Product Sharing n/a CVE
CRITICAL 9.8 CVE-2026-54419

PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query_CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) con...

claudiopizzillo PIAF-HMS CVE
MEDIUM 6.5 CVE-2026-44942

libzypp .repo files can have an optional path which can lead to path traversal attacks_CVE-2026-44942

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could ...

SUSE libzypp 17.0.0 CVE
HIGH 8.8 CVE-2026-8461

Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder_CVE-2026-8461

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some ca...

FFmpeg FFmpeg CVE
MEDIUM 5.9 CVE-2026-56009

WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored X...

Bricksable Bricksable for Bricks Builder n/a CVE