📂 WooCommerce Plugin Flaw Exposes Arbitrary Files
Administrators using the affected WooCommerce plugin should patch promptly or remove the vulnerable version. The unauthenticated file access capability makes this important to address quickly.
CVE-2026-15019 affects the Direct Download for WooCommerce plugin for WordPress and allows unauthenticated directory traversal through the top-level include function. Attackers can read arbitrary files on affected servers, potentially exposing sensitive information. It is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🔑 WordPress Plugin Bug Enables Account Takeover
Sites using the affected plugin should update as soon as possible and review access controls around affected accounts. The ability to gain administrator access makes this a high-priority fix.
CVE-2026-14873 affects the Bulk Password Reset plugin for WordPress and allows privilege escalation through account takeover. Authenticated users with subscriber-level access or above can change user details, including administrator credentials, due to improper identity validation. It is rated HIGH with CVSS 8.0.
🔗 Read more 🔗
Source: NVD
📤 Editor Upload Vulnerability May Enable Code Execution
Teams using affected BurgerEditor versions should update quickly and limit access to trusted users where possible. The upload weakness can have serious impact if exploited.
CVE-2026-84063 affects BurgerEditor versions 3.2.0 through 3.4.0 and involves unrestricted upload of dangerous file types. Attackers who can log in may upload arbitrary files, potentially allowing PHP code execution. It is rated HIGH with CVSS 8.5.
🔗 Read more 🔗
Source: NVD
🦎 Velociraptor Backup Flaw Allows Elevated Query Execution
Velociraptor administrators should patch and review users with notebook editing permissions. The issue affects environments where backup restoration workflows are used.
CVE-2026-19584 affects Velociraptor notebook backup restoration and allows malicious notebook content to execute without ACL checks. A user with NOTEBOOK_EDITOR permission can plant a VQL query that runs with elevated permissions when a backup is restored. It is rated HIGH with CVSS 7.7.
🔗 Read more 🔗
Source: NVD
🚨 Critical Permission Bypass Impacts Endpoint Control
Organizations using Velociraptor should apply the fix urgently and review who can schedule client monitoring artifacts. The vulnerability can allow unauthorized execution capabilities on endpoints.
CVE-2026-19583 affects Velociraptor client monitoring artifacts and allows users to schedule restricted artifacts without required permission checks. This can allow access to actions such as Linux.Sys.BashShell command execution on endpoints. It is rated CRITICAL with CVSS 9.9.
🔗 Read more 🔗
Source: NVD
⚠️ Elementor Forms Upload Bug Allows Remote Code Execution
WordPress administrators using the affected plugin should patch immediately or disable the vulnerable functionality until fixed. The unauthenticated remote code execution risk makes this a top priority.
CVE-2026-18351 affects the Drag and Drop File Upload for Elementor Forms plugin for WordPress and allows arbitrary file uploads. Unauthenticated attackers can upload executable files due to insufficient file type validation, potentially leading to remote code execution. It is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🐞 cJSON Memory Bug Has Public Exploit
Developers using affected cJSON versions should update when a fix is available. Public exploit availability increases the urgency for applications processing untrusted JSON.
CVE-2026-87933 affects DaveGamble cJSON up to 1.7.19 and is caused by a use after free issue in cJSONUtils_MergePatch. The vulnerability can be launched remotely, and the exploit has been made public. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
⌚ Wearable Device Buffer Overflow Disclosed
Users and administrators managing affected devices should check for available updates and reduce unnecessary network exposure. The disclosed buffer overflow should be treated seriously.
CVE-2026-87931 affects the Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. The issue involves a buffer overflow in the Apple Notification Center Service Event Handler and requires an attack from the local network. It is rated CRITICAL with CVSS 9.6.
🔗 Read more 🔗
Source: NVD
💾 Inventory System SQL Injection Has Public Exploit
Users of the affected inventory system should prioritize applying available fixes and assess exposed deployments. Public exploit availability increases the risk of exploitation.
CVE-2026-87925 affects Rizwan17 inventory-management-system and allows SQL injection through the storeCustomerOrderInvoice function. The attack can be launched remotely, and the exploit is now public. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
📦 Pandora Archive Processing Bug Enables Path Traversal
Pandora administrators should apply the fix promptly and review systems that process submitted archives or disk images. The ability to write outside the intended directory creates a serious risk.
CVE-2026-88069 affects Pandora and contains a path traversal vulnerability in its archive extraction worker. Crafted archives or disk images can write files outside the intended extraction directory, potentially modifying application or system files. It is rated CRITICAL with CVSS 9.3.
🔗 Read more 🔗
Source: NVD
🤖 Open WebUI Cloud Resource Access Flaw
Open WebUI administrators should upgrade to version 0.11.1 and review user access permissions. Cloud-hosted instances should be addressed promptly.
CVE-2026-87999 affects Open WebUI versions before 0.11.1 and allows authenticated users to retrieve content from protected Azure-reserved addresses. The issue is caused by incorrect destination validation in web retrieval functions. It is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD
🧠 Open WebUI Authorization Bug Disrupts Shared Resources
Open WebUI administrators should upgrade and review users with knowledge base write permissions. Shared configurations using affected connections may be impacted.
CVE-2026-87998 affects Open WebUI versions from 0.10.0 until 0.11.1 and allows non-administrator users to remove administrator-owned external connections. A user with write access to one knowledge base could make other knowledge bases using the same connection unavailable. It is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD