5.4
CVE-2026-0901 -
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
5.3
CVE-2025-14798 - LearnPress โ WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive Uโฆ
The LearnPress โ WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and laโฆ
5.3
CVE-2025-14351 - Custom Fonts โ Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deโฆ
The Custom Fonts โ Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated atโฆ
4.3
CVE-2026-1051 - Newsletter โ Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletterโฆ
The Newsletter โ Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticatedโฆ
5.3
CVE-2025-14978 - PeachPay โ Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.โฆ
The PeachPay โ Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all versions up to, and including, 1.119โฆ
6.3
CVE-2026-1203 - CRMEB JSON Token LoginServices.php remoteRegister improper authentication
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication. The attack may be perโฆ
6.9
CVE-2026-1202 - CRMEB LoginController.php appleLogin improper authentication
A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remoteโฆ
8.1
CVE-2026-23876 - Heap buffer overflow with attacker-controlled data in XBM parser
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when proceโฆ
5.5
CVE-2026-23874 - ImageMagick's MSL: Stack overflow via infinite recursion in ProcessMSLScript
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.
6.5
CVE-2026-22770 - ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation fails
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will resulโฆ