{"resultsPerPage":33,"startIndex":0,"totalResults":33,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-27T12:14:06.344","vulnerabilities":[{"cve":{"id":"CVE-2025-15662","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:23.680","lastModified":"2026-07-27T07:16:23.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Printcart Web to Print Product Designer for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.5.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6294afde-d23a-4634-a49a-168ce463278c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-10082","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.183","lastModified":"2026-07-27T07:16:24.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Ads  WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Advanced Ads","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.23","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/088a832d-2153-432e-849f-2c22b63a1b54/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-12255","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.283","lastModified":"2026-07-27T07:16:24.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MainWP Child  WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MainWP Child","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6ecd37bf-f48a-4f7f-8a93-e7f0475371af/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-12394","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.383","lastModified":"2026-07-27T07:16:24.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MemberGlut  WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MemberGlut","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6b126a3e-30d5-4bed-ba47-33e589ec2852/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-12493","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.480","lastModified":"2026-07-27T07:16:24.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase)."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Clover Payment Gateway by Zaytech for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.3.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b9f3f6d8-b56f-4d0e-9102-c69e6756ab74/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-12982","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.577","lastModified":"2026-07-27T07:16:24.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Document Gallery","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a3c279ce-5db1-4331-ad74-4eef49619737/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13152","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.697","lastModified":"2026-07-27T07:16:24.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Custom Fields Account Registration For Woocommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/36aaba38-3143-4e80-8386-748632ff6704/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13332","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.820","lastModified":"2026-07-27T07:16:24.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Masteriyo LMS  WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Masteriyo LMS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f987c823-f215-48f6-86fe-8d898f2c2d94/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13390","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:24.930","lastModified":"2026-07-27T07:16:24.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"The Events Calendar","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.16.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c7d3b1c5-3b3a-4359-aa41-0dfccb091fa4/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13400","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.023","lastModified":"2026-07-27T07:16:25.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Simply Schedule Appointments","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.6.12.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/501b2929-3216-4587-8124-088fd51becf1/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13597","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.127","lastModified":"2026-07-27T07:16:25.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"微信二维码登陆","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/5e856219-ece5-4d79-8375-fc0cbdc37d6c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13714","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.227","lastModified":"2026-07-27T07:16:25.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Realtyna Organic IDX plugin + WPL Real Estate","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/69f9dcd8-ab3c-46ed-ac6b-2f1db35f8d1f/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13726","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.320","lastModified":"2026-07-27T07:16:25.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MPG  WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MPG","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/4f97b6c6-c05b-4ea5-987d-d289b89cdea8/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14189","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.413","lastModified":"2026-07-27T07:16:25.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WPBot  WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"WPBot","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"8.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/e25ea94a-f5a0-4cae-975b-9e0a45af6bc2/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14190","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.510","lastModified":"2026-07-27T07:16:25.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Sina Extension for Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/9b855913-a55e-469d-b3cd-324c31b0d4d8/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14203","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.607","lastModified":"2026-07-27T07:16:25.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Smart Manager  WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Smart Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"8.92.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/efcaa453-80f3-4565-a4f8-eefa231d77b6/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14235","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.700","lastModified":"2026-07-27T07:16:25.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Download Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.3.62","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/9634b51c-59a1-45f6-8b09-421d6bfd0204/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14236","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.797","lastModified":"2026-07-27T07:16:25.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contact Form 7  WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Contact Form 7","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.5","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b53cc13d-c59e-4c11-aa71-fa1c38c2a34d/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14289","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.890","lastModified":"2026-07-27T07:16:25.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FacturaONE para WooCommerce con VeriFactu","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.37","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f08365f6-57d2-475a-82c8-c4d27286569e/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14568","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:25.987","lastModified":"2026-07-27T07:16:25.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/dcbc2a0c-6fa6-4266-9292-0a1f3418da08/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14820","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:26.083","lastModified":"2026-07-27T07:16:26.083","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Quiz and Survey Master (QSM)","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"11.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/22af8c73-8147-4205-8285-a35881f2d041/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14827","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:26.180","lastModified":"2026-07-27T07:16:26.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Calendar","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.3.18","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b2981b41-b712-43d9-a327-3a376346cec5/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-66412","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-07-27T07:16:30.317","lastModified":"2026-07-27T07:16:30.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the JSON-RPC API to access project planning information, milestone titles, descriptions, and timelines across all projects on the instance regardless of project membership."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Leantime","product":"Leantime","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"3.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/Leantime/leantime/commit/68898eeb914882a21797523f2782914795bc67ae","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Leantime/leantime/pull/3657","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Leantime/leantime/security/advisories/GHSA-wv69-xr82-phr6","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/leantime-all-versions-prior-to-and-broken-access-control-via-tickets-getmilestone-json-rpc","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-9830","sourceIdentifier":"contact@wpscan.com","published":"2026-07-27T07:16:30.503","lastModified":"2026-07-27T07:16:30.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"bookingpress-appointment-booking-pro","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.7.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/5fded411-52fd-4dc5-9a23-b77fcd9cfed2/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14837","sourceIdentifier":"info@cert.vde.com","published":"2026-07-27T08:16:17.463","lastModified":"2026-07-27T08:16:17.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise."}],"affected":[{"source":"info@cert.vde.com","affectedData":[{"vendor":"Lenze","product":"c430","defaultStatus":"unaffected","versions":[{"version":"1.0.0","lessThan":"1.15.2","versionType":"semver","status":"affected"}]},{"vendor":"Lenze","product":"c520","defaultStatus":"unaffected","versions":[{"version":"1.0.0","lessThan":"1.15.2","versionType":"semver","status":"affected"}]},{"vendor":"Lenze","product":"c550","defaultStatus":"unaffected","versions":[{"version":"1.0.0","lessThan":"1.15.2","versionType":"semver","status":"affected"}]},{"vendor":"Lenze","product":"i950 GenA","defaultStatus":"unaffected","versions":[{"version":"1.0.0","lessThan":"1.14.2","versionType":"semver","status":"affected"}]},{"vendor":"Lenze","product":"i950 GenB","defaultStatus":"unaffected","versions":[{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"info@cert.vde.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"info@cert.vde.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"info@cert.vde.com","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2026-077/","source":"info@cert.vde.com"}]}},{"cve":{"id":"CVE-2026-64531","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.243","lastModified":"2026-07-27T08:16:22.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reject oversized nested action attrs\n\nOpen vSwitch stores generated flow actions as nlattrs, whose nla_len\nfield is u16. Commit a1e64addf3ff (\"net: openvswitch: remove\nmisbehaving actions length check\") allowed the total sw_flow_actions\nstream to grow beyond 64 KiB, which is valid, but also removed the last\nguard preventing a generated nested action attribute from exceeding\nU16_MAX.\n\nAn oversized generated container can thus be closed with a truncated\nnla_len. A later dump or teardown then walks a structurally different\nstream than the one that was validated. In particular, an oversized\nnested CLONE/CT action may cause subsequent bytes in the generated\nstream to be interpreted as independent actions.\n\nKeep the larger total-action-stream behavior, but make nested action\nclose reject generated containers that do not fit in nla_len, and return\nthe error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and\nCHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse\nconstruction order before discarding failed wrappers, so resources copied\ninto the rejected tails are released before the wrappers are removed.\n\nMost failed outer wrappers are discarded by truncating actions_len after\nchild resources have been released. CHECK_PKT_LEN also trims its parent\nafter branch resources are gone. SET/TUNNEL close failures unwind their\nknown tun_dst ownership directly, and SET_TO_MASKED has no external\nownership and truncates on close failure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/openvswitch/flow_netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"057dbc5b72e9fcac439cd561c3a539b8a0edeb92","lessThan":"ab855641241387db062a5e41d9ad6b8561542572","versionType":"git","status":"affected"},{"version":"2532adbfe917c0e71dba2650ffc6efe396314c87","lessThan":"c66bd2626c2764f23764ff0f8277f44a9cfe8349","versionType":"git","status":"affected"},{"version":"4b1a0ee6164c7204c68ab5a9c48c07bfe8852485","lessThan":"d573250d228401f707f4dbc09d11227a6215ee5f","versionType":"git","status":"affected"},{"version":"e6610f9c08b4c04cf7949c10fc246c071d00e935","lessThan":"f1efff8858403191361a01269c6fe8dd7f55a385","versionType":"git","status":"affected"},{"version":"a1e64addf3ff9257b45b78bc7d743781c3f41340","lessThan":"dbd14f736be02cfe73049bd801af89becd1a0749","versionType":"git","status":"affected"},{"version":"a1e64addf3ff9257b45b78bc7d743781c3f41340","lessThan":"1b41cbe05b184f8861712f0806cc0c4f5d8c6dfe","versionType":"git","status":"affected"},{"version":"a1e64addf3ff9257b45b78bc7d743781c3f41340","lessThan":"3f1f755366687d051174739fb99f7d560202f60b","versionType":"git","status":"affected"},{"version":"6b099d285d7ed324494b6d684f377aa103856118","versionType":"git","status":"affected"},{"version":"5.15.180","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.132","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.84","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.20","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.13.8","lessThan":"6.14","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/openvswitch/flow_netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b41cbe05b184f8861712f0806cc0c4f5d8c6dfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f1f755366687d051174739fb99f7d560202f60b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab855641241387db062a5e41d9ad6b8561542572","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c66bd2626c2764f23764ff0f8277f44a9cfe8349","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d573250d228401f707f4dbc09d11227a6215ee5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbd14f736be02cfe73049bd801af89becd1a0749","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1efff8858403191361a01269c6fe8dd7f55a385","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64532","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.383","lastModified":"2026-07-27T08:16:22.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}\n\nIn do_action()'s UpdateRecordDataRoot (fslog.c:3489) and\nUpdateRecordDataAllocation (fslog.c:3697) cases, the memmove\ndestination is `Add2Ptr(e, le16_to_cpu(e->view.data_off))`,\nwhere e->view.data_off comes from an on-disk NTFS_DE inside\nan INDEX_ROOT or INDEX_BUFFER.  Neither case validates\nview.data_off + dlen against e->size; the existing\ncheck_if_index_root / check_if_alloc_index helpers walk the\nentry chain and validate the entry's offset, but not its\ninternal view fields.\n\nThe neighbouring read sites (e.g., fs/ntfs3/index.c when\niterating view entries) check view.data_off + view.data_size\n<= e->size.  Apply the same bound at the two memmove sites.\n\nReproduced under UML+KASAN on mainline 8d90b09e6741 via\npr_warn-only probe instrumentation: with view.data_off forced\nto 0xFFFC, the memmove writes 32 bytes past the end of the\nNTFS_DE.\n\nThis is similar in shape to Pavitra Jha's 2026-05-02 patch\n\"fs/ntfs3: prevent oob in case UpdateRecordDataRoot\"\n(<20260502105008.21827-1-jhapavitra98@gmail.com>) which\nproposes calling ntfs3_bad_de_range(); that helper does not\nexist in mainline.  This patch uses inline checks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"b20e5a709d8bd190d6e4645606763c7423e694c1","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"d41b382068ca4e64e421f736cdd700095464b6ac","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"429d653ca641d38a78609b8f62e81a0a5c780a2d","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"315d3a9a48b49f889da3d858a9307e677cb9e1bd","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"be306b8d9143a9c076c804a7ca025d69caf9c448","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"36feda687afebae24c472202694448738809c411","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"3e127829e57f5190f612412ece4541cb96d5ec7a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/315d3a9a48b49f889da3d858a9307e677cb9e1bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36feda687afebae24c472202694448738809c411","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e127829e57f5190f612412ece4541cb96d5ec7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/429d653ca641d38a78609b8f62e81a0a5c780a2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b20e5a709d8bd190d6e4645606763c7423e694c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be306b8d9143a9c076c804a7ca025d69caf9c448","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d41b382068ca4e64e421f736cdd700095464b6ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64533","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.510","lastModified":"2026-07-27T08:16:22.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate lcns_follow in log_replay conversion\n\nlog_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY\nrecords when replaying version 0 restart tables.\n\nDuring this conversion, the memmove() length is derived directly from\nthe on-disk lcns_follow field:\n\n\tmemmove(&dp->vcn, &dp0->vcn_low,\n\t\t2 * sizeof(u64) +\n\t\t\t\tle32_to_cpu(dp->lcns_follow) * sizeof(u64));\n\ncheck_rstbl() validates restart table structure, but does not constrain\nper-entry lcns_follow values relative to the entry size. A malformed\nfilesystem image can provide an oversized lcns_follow value, causing\nthe conversion memmove() to access memory beyond the bounds of the\nallocated restart table buffer.\n\nThe same field is later used to bound iteration over page_lcns[],\nso validating lcns_follow during conversion also prevents downstream\nout-of-bounds access from the same malformed metadata.\n\nCompute the maximum valid lcns_follow from the already-validated\nrestart table entry size and reject entries that exceed this bound.\nReuse the existing t16/t32 scratch variables already declared in\nlog_replay() to avoid introducing new declarations.\n\n[almaz.alexandrovich@paragon-software.com: fixed the conflicts]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"ca343a99806b4fc8e27c48f08be3445c5fcd1445","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"ddfc8683e1a627dbf1b83bacf8961443dd654258","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"57c071e2c4f30b9c6f5aacb6679aab1269fbae99","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"159f694d682e4215b3822ae31ed3a4631628fe55","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"7adb38279812c9c06b0e3fa7382f4d7887f3fa2d","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"32b9f8733feb241627fa5f564b1a99b5cae974c5","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"6a4c53a2e26a865565bd6a460961e8d6fcb32329","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64534","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.643","lastModified":"2026-07-27T08:16:22.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is called unconditionally. However, if the command\narrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()\nhad returned false and percpu_ref_tryget_live() was never executed. The\nunconditional percpu_ref_put() inside nvmet_req_uninit() then causes a\nrefcount underflow, leading to a WARNING in\npercpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and\neventually a permanent workqueue deadlock.\n\nCheck cmd->flags & NVMET_TCP_F_INIT_FAILED before calling\nnvmet_req_uninit(), matching the existing pattern in\nnvmet_tcp_execute_request()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c7874dad84b20433c0fe3919f291a762d40de08b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d306da8833e75f669d93424fd84940236f3850bc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2ed3c9d955e8cd6361f130623baa664a75fb345f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4606467a75cfc16721937272ed29462a750b60c8","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64535","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.773","lastModified":"2026-07-27T08:16:22.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch occurs on a non-final H2C_DATA PDU during an R2T-based\ndata transfer, the digest error handler in nvmet_tcp_try_recv_ddgst()\ncalls nvmet_req_uninit() — which performs percpu_ref_put() on the\nsubmission queue — but does NOT mark the command as completed. It\ndoes not set cqe->status, does not modify rbytes_done, and does not\nclear any flag. When the subsequent fatal error triggers queue\nteardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands,\nchecks nvmet_tcp_need_data_in() for each one, and finds that the\nalready-uninited command still appears to need data (because\nrbytes_done < transfer_len and cqe->status == 0). It therefore calls\nnvmet_req_uninit() a second time on the same command — a double\npercpu_ref_put against a single percpu_ref_get."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"96fe2513df590e74b04253a45089cae75569570e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e091ff83d962f9ed00d9bd70443676de9fe98bdc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6f9442983a3e4227afd1c83a5251ddbca585ea21","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"088ee46c18d99baef453afd74181dd40ade044ad","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64536","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.890","lastModified":"2026-07-27T08:16:22.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop\n\nThe loop in is_ap_in_tkip() iterates over IEs without verifying that\nenough bytes remain before dereferencing the IE header or its payload:\n\n- pIE->element_id and pIE->length are read without checking that\n  i + sizeof(*pIE) <= ie_length, so a truncated IE at the end of the\n  buffer causes an OOB read.\n\n- For WLAN_EID_VENDOR_SPECIFIC the code compares pIE->data + 12,\n  which requires pIE->length >= 16.  For WLAN_EID_RSN it compares\n  pIE->data + 8, requiring pIE->length >= 12.  Neither requirement\n  is checked.\n\nAdd the missing IE header and payload bounds checks and guard each\ndata access with an explicit pIE->length minimum, matching the\npattern established in update_beacon_info()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ea3809f7e20bdff282b8cc1e94937d5fb9fb32c7","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"d2055332297e24c63fffda943ef7a5eefc0a6019","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6f26cc55affd9d7f88ae2f5d12db4ecf9072c209","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"204b22c8df115370037248859bf0fa62db73a396","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a6105ea8ca6ebbc04beaf3bcbf7dbb5985f5d395","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4380b3860d887a13555ff024a58dfc05b490dfd6","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"3bf39f711ff27c64be8680a8938bcc5001982e81","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/204b22c8df115370037248859bf0fa62db73a396","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bf39f711ff27c64be8680a8938bcc5001982e81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4380b3860d887a13555ff024a58dfc05b490dfd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f26cc55affd9d7f88ae2f5d12db4ecf9072c209","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6105ea8ca6ebbc04beaf3bcbf7dbb5985f5d395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2055332297e24c63fffda943ef7a5eefc0a6019","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea3809f7e20bdff282b8cc1e94937d5fb9fb32c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-65893","sourceIdentifier":"vdisclose@cert-in.org.in","published":"2026-07-27T08:16:23.010","lastModified":"2026-07-27T08:16:23.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.\n\nAn attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.\n\n\n\nSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device."}],"affected":[{"source":"vdisclose@cert-in.org.in","affectedData":[{"vendor":"CP-Plus","product":"EZ-P21 IP Camera","defaultStatus":"unaffected","versions":[{"version":"version v4.8.8.1 and prior","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vdisclose@cert-in.org.in","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"vdisclose@cert-in.org.in","type":"Primary","description":[{"lang":"en","value":"CWE-489"}]}],"references":[{"url":"https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0380","source":"vdisclose@cert-in.org.in"}]}},{"cve":{"id":"CVE-2026-65894","sourceIdentifier":"vdisclose@cert-in.org.in","published":"2026-07-27T08:16:23.157","lastModified":"2026-07-27T08:16:23.157","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.\n\n\n\nSuccessful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device."}],"affected":[{"source":"vdisclose@cert-in.org.in","affectedData":[{"vendor":"CP-Plus","product":"EZ-P21 IP Camera","defaultStatus":"unaffected","versions":[{"version":"version v4.8.8.1 and prior","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vdisclose@cert-in.org.in","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"vdisclose@cert-in.org.in","type":"Primary","description":[{"lang":"en","value":"CWE-307"}]}],"references":[{"url":"https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0380","source":"vdisclose@cert-in.org.in"}]}}]}