-Infinity
0

WordPress WordPressWordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Risk 66
Severity
9.1
First published (updated )

Vimesoft Enterprise Video PlatformMissing Authorization in Vimesoft's Enterprise Video Platform

Risk 66
Severity
9.1
First published (updated )

Vimesoft Enterprise Video PlatformIDOR in Vimesoft's Enterprise Video Platform

Risk 76
Severity
9.4
First published (updated )

Vimesoft Enterprise Video PlatformImproper Authentication in Vimesoft's Enterprise Video Platform

Risk 86
Severity
9.8
First published (updated )

Sangoma Switchvox SMB EditionUnauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

Risk 84
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management SystemSQLi in GIS Informatics' GisLab Laboratory Management System

Risk 86
Severity
9.8
First published (updated )

HCL Aftermarket EPCWeak Encryption

Risk 66
Severity
9.1
First published (updated )

AIWU AI Copilot WordPress pluginAI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth

Risk 61
Severity
9.8
EPSS
0.14%
First published (updated )

WordPress pluginAimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'

Risk 86
Severity
9.8
First published (updated )

Bricksforge WordPress Bricksforge pluginBricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

clawvet self-hosted API server (apps/api)clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery

Risk 67
Severity
9.3
First published (updated )

Grav GravGrav < 2.0.4 2FA Bypass via Secret Regeneration

Risk 63
Severity
9.1
First published (updated )

redhat/kernel-rtCritical: kernel-rt security, bug fix, and enhancement update

Risk 42
Severity
9
First published (updated )

libpvestorage-perlXEE

Risk 86
Severity
9.8
First published (updated )

YAML::Syck YAML::SyckYAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec

Risk 70
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Zoom Zoom Desktop Client for WindowsZoom Workplace VDI Plugin for Windows - Improper Input Validation

Risk 89
Severity
9.8
First published (updated )

composer/pheditor/pheditor### Summary Pheditor ships with a hardcoded default password `admin` (SHA-512 hash stored at `phedi…

Risk 86
Severity
9.8
First published (updated )

composer/pheditor/pheditor### Summary Pheditor ships with a hardcoded default password `admin` (SHA-512 hash stored at `phedi…

Risk 86
Severity
9.8
First published (updated )

illumos SCTPSCTP needs to better-check INIT ACK chunk parameters

Risk 84
Severity
9.1
First published (updated )

WireGuard WireGuard EasyWireGuard Easy Weak Token Generation Information Disclosure via OTL Route

Risk 61
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/envoyproxy/gatewayInput Validation

Risk 66
Severity
9.1
First published (updated )

go/github.com/envoyproxy/gatewayInput Validation

Risk 66
Severity
9.1
First published (updated )

Frogman Frogman (headless PBX control via MCP and HTTP API)Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution

Risk 64
Severity
9.3
First published (updated )

Frogman Frogman headless PBX control (MCP and HTTP API)Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping

Risk 82
Severity
9.9
First published (updated )

HireFlow HireFlowHireFlow: Use of Hard-coded Credentials

Risk 82
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Image::EPEGImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library

Risk 86
Severity
9.8
First published (updated )

Perl/XML::BareXML::Bare versions through 0.53 for Perl have an unbounded character lookahead

Risk 70
Severity
9.1
First published (updated )

Perl HTML::BareHTML::Bare versions through 0.04 for Perl have an unbounded character lookahead

Risk 70
Severity
9.1
First published (updated )

Grafana OnCallGrafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint

Risk 86
Severity
9.3
First published (updated )

Microsoft Microsoft 365 and Microsoft Entra ID Plugins for Moodlemoodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint

Risk 84
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203