Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-53357In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned sk has no caller reference and is unlocked. l2cap_sock_cleanup_listen() walks these children on listening-socket close. A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l2cap_chan_del() + l2cap_sock_kill() and frees the child sk and its l2cap_chan; cleanup_listen() then uses both: BUG: KASAN: slab-use-after-free in l2cap_sock_kill l2cap_sock_kill / l2cap_sock_cleanup_listen / __x64_sys_close Freed by: l2cap_conn_del -> l2cap_sock_close_cb -> l2cap_sock_kill This is distinct from the two fixes already in this area: commit e83f5e24da741 ("Bluetooth: serialize accept_q access") serialises the accept_q list/poll and takes temporary refs inside bt_accept_dequeue(), and CVE-2025-39860 serialises the userspace close()/accept() race by calling cleanup_listen() under lock_sock() in l2cap_sock_release(). Neither covers l2cap_conn_del() running from hci_rx_work, so this UAF still reproduces on current bluetooth/master. Take the reference at the source: bt_accept_dequeue() does sock_hold() while sk is still locked, before release_sock(); callers sock_put(). cleanup_listen() pins the chan with l2cap_chan_hold_unless_zero() under a brief child sk lock (serialising vs l2cap_sock_teardown_cb()), drops it before l2cap_chan_lock(), and skips a duplicate l2cap_sock_kill() on SOCK_DEAD. conn->lock is not taken here: cleanup_listen() runs under the parent sk lock and that would invert conn->lock -> chan->lock -> sk_lock (lockdep). KASAN/SMP: an unprivileged listen/close vs HCI-disconnect race produced 12 use-after-free reports per run before this change; 0, and no lockdep report, over 1600+ raced iterations after it on bluetooth/master.
high
2026-07-22
CVE-2026-50748A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
critical
2026-07-09
CVE-2026-50747A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
critical
2026-07-09
CVE-2026-50746A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
critical
2026-07-09
CVE-2026-12168An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.
high
2026-07-02
CVE-2026-12167The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.
high
2026-07-02
CVE-2026-12166A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests that trigger a system crash.
medium
2026-07-02
CVE-2026-4767Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
critical
2026-07-02
CVE-2026-58653PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.
medium
2026-07-02
CVE-2026-58652luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI 'script' and 'script_args' values and executes the configured path when the captive-portal auto-login branch (f_check() in travelmate-functions.sh) is reached. An attacker with delegated write permissions can set script to /bin/sh and script_args to attacker-controlled arguments, resulting in arbitrary command execution as root. Confirmed in luci-app-travelmate/travelmate 2.4.5-r3; the sink is still present in travelmate 2.4.6-1 and no patched version is known.
high
2026-07-02
CVE-2026-5524The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is completely ineffective as Nginx does not process .htaccess files. This makes it possible for unauthenticated attackers (who can obtain a nonce from any public page containing a form) to upload executable PHP files to the publicly accessible /wp-content/uploads/de_fb_uploads/ directory and achieve Remote Code Execution by accessing the uploaded file via HTTP. The vulnerability was partially patched in version 5.1.3.
critical
2026-07-02
CVE-2026-4772Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
medium
2026-07-02
CVE-2026-4770Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
medium
2026-07-02
CVE-2026-57766Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
high
2026-07-02
CVE-2026-57765Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
high
2026-07-02
CVE-2026-57764Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
medium
2026-07-02
CVE-2026-57763Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
medium
2026-07-02
CVE-2026-57762Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
medium
2026-07-02
CVE-2026-57761Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
high
2026-07-02
CVE-2026-57760Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
medium
2026-07-02
CVE-2026-57759Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
high
2026-07-02
CVE-2026-57758Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
high
2026-07-02
CVE-2026-57757Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
high
2026-07-02
CVE-2026-57756Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
high
2026-07-02
CVE-2026-57755Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.
medium
2026-07-02
CVE-2026-57754Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
medium
2026-07-02
CVE-2026-57753Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
medium
2026-07-02
CVE-2026-57752Contributor SQL Injection in iNET Webkit 1.2.4 versions.
high
2026-07-02
CVE-2026-57751Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
high
2026-07-02
CVE-2026-57750Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
medium
2026-07-02
CVE-2026-57749Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
high
2026-07-02
CVE-2026-57748Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
high
2026-07-02
CVE-2026-57747Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
medium
2026-07-02
CVE-2026-57746Subscriber Broken Access Control in Booked <= 3.0.0 versions.
high
2026-07-02
CVE-2026-57731Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
medium
2026-07-02
CVE-2026-57730Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
medium
2026-07-02
CVE-2026-57690Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
medium
2026-07-02
CVE-2026-57689Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
medium
2026-07-02
CVE-2026-57688Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
high
2026-07-02
CVE-2026-57687Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
high
2026-07-02
CVE-2026-57686Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
high
2026-07-02
CVE-2026-57685Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
medium
2026-07-02
CVE-2026-57684Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.
medium
2026-07-02
CVE-2026-57683Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
critical
2026-07-02
CVE-2026-57682Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
high
2026-07-02
CVE-2026-57681Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
medium
2026-07-02
CVE-2026-57680Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
medium
2026-07-02
CVE-2026-57679Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
critical
2026-07-02
CVE-2026-57678Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
high
2026-07-02
CVE-2026-57677Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
critical
2026-07-02