Aggregator
CVE-2026-42645 | Dmitry V. Barcode Scanner with Inventory & Order Manager Plugin cross-site request forgery
Google Chrome security advisory (AV26-402)
CVE-2026-42641 | ILLID Share This Image Plugin up to 2.14 on WordPress server-side request forgery
CVE-2026-42646 | Steve Burge TaxoPress Plugin up to 3.44.0 on WordPress sql injection
CVE-2026-42642 | StellarWP GiveWP Plugin up to 4.14.5 on WordPress authorization
CVE-2026-42644 | WPDeveloper BetterDocs Plugin up to 4.3.10 on WordPress exposure of sensitive system information to an unauthorized control sphere
CVE-2026-22740 | Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 Multipart Request resource consumption
CVE-2026-42648 | Brainstorm Force Spectra Plugin up to 2.19.22 on WordPress authorization
CVE-2026-7400 | geekgod382 filesystem-mcp-server 1.0.0 read_file_tool/write_file_tool server.py is_path_allowed path traversal
Submit #803525: SourceCodester CET Automated Grading System with AI Predictive Analytics in PHP and MySQL 1.0 Cross Site Scripting [Accepted]
CVE-2026-42515 | CDAC-Noida e-Sushrut Hospital Management Information System API Request authorization (CIVN-2026-0207 / EUVD-2026-26198)
CVE-2026-42516 | CDAC-Noida e-Sushrut Hospital Management Information System encoded authorization (CIVN-2026-0207 / EUVD-2026-26201)
CVE-2026-4019 | Complianz Plugin up to 7.4.5 on WordPress REST API Endpoint cmplz_rest_consented_content authorization (EUVD-2026-26200)
CVE-2026-42518 | CDAC-Noida e-Sushrut Hospital Management Information System hard-coded key (CIVN-2026-0207 / EUVD-2026-26204)
CVE-2026-42517 | CDAC-Noida e-Sushrut Hospital Management Information System Base64 Encoding authorization (CIVN-2026-0207 / EUVD-2026-26203)
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially added this security flaw to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability impacts the Microsoft Windows Shell and is actively being exploited in real-world attacks. Organizations worldwide […]
The post CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks appeared first on Cyber Security News.
Submit #803495: geekgod382 filesystem-mcp-server 4e3e83852b1395de0a437bd4fd66376422f4ea0c Path Traversal [Accepted]
Игрушка-психолог, игрушка-учитель, игрушка-шпион. Знакомьтесь: ИИ-компаньон для вашего ребёнка
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks
A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked as CVE-2026-25874 with a critical CVSS score of 9.3, the flaw allows unauthenticated attackers to execute arbitrary system commands on vulnerable host machines. With nearly 24,000 stars on GitHub, this […]
The post Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks appeared first on Cyber Security News.