-Infinity
0

Fluent Forms Fluent Forms Pro Add On PackFluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field

Risk 79
Severity
8.8
First published (updated )

WPForms ProWPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

Risk 75
Severity
8.1
First published (updated )

Knot Resolver Knot ResolverBuffer Overflow

Risk 62
Severity
8.1
First published (updated )

Redis redisDouble Free

Risk 70
Severity
7.5
First published (updated )

pip/bedrock-agentcoreInput Validation

Risk 54
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/aws-smithy-http-server## Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and…

Risk 43
Severity
7.5
First published (updated )

pip/libp2p### Summary The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths …

Risk 43
Severity
7.5
First published (updated )

go/github.com/jandedobbeleer/oh-my-poshCode Injection

Risk 68
Severity
7.8
First published (updated )

maven/org.omnifaces:omnifacesXSS, SSRF

Risk 43
Severity
7.5
First published (updated )

pip/awslabs.aws-api-mcp-server## Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables…

Risk 62
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/OpenListTeam/OpenList/v4Path Traversal, SQL Injection

Risk 58
Severity
7.6
First published (updated )

maven/org.http4s:http4s-blaze-server_2.13## Summary `http4s-blaze-server` aggregates the fragments of an incoming WebSocket message with no …

Risk 43
Severity
7.5
First published (updated )

maven/org.http4s:blaze-http_3### Summary blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Be…

Risk 56
Severity
7.4
First published (updated )

maven/org.http4s:blaze-http_2.13### Summary Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`h…

Risk 56
Severity
7.4
First published (updated )

Weintek cMT3092X HMIWeintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Weintek cMT3092X HMIWeintek cMT3092X Incorrect Permission Assignment for Critical Resource

Risk 79
Severity
8.7
First published (updated )

Weintek cMT3092X HMIWeintek cMT3092X Plaintext Storage of a Password

Risk 40
Severity
7.1
First published (updated )

Weintek cMT3092XWeintek cMT3092X Incorrect User Management

Risk 40
Severity
7.1
First published (updated )

composer/poweradmin/poweradmin## Preface Poweradmin maps OIDC identities into local users through `oidc_user_links.oidc_subject` …

Risk 60
Severity
8.1
First published (updated )

composer/poweradmin/poweradminSQL Injection, CSRF

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/poweradmin/poweradmin### Summary The REST API user-update endpoint (`PUT/PATCH /api/v2/users/{id}` and the V1 equivalent…

Risk 79
Severity
8.8
First published (updated )

npm/brace-expansion### Summary `expand()` bounds the *number* of results it produces (the `max` option, `100_000` by d…

Risk 43
Severity
7.5
First published (updated )

npm/@anephenix/hub### Summary `@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket conne…

Risk 43
Severity
7.5
First published (updated )

composer/pheditor/pheditorOS Command Injection

Risk 79
Severity
8.8
First published (updated )

pip/GitPythonInfoleak

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@budibase/serverSSRF

Risk 73
Severity
8.5
First published (updated )

npm/@budibase/serverSQL Injection

Risk 48
Severity
7.1
First published (updated )

npm/@budibase/serverCSRF, XSS

Risk 55
Severity
7.7
First published (updated )

npm/@budibase/serverSQL Injection

Risk 60
Severity
7.6
First published (updated )

npm/@budibase/serverSQL Injection, Input Validation

Risk 69
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203