8.8
CVE-2026-33848 - Improper Restriction of Operations within the Bounds of a Memory Buffer in linkingvision rapidvms
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
7.8
CVE-2026-33851 - Improper Restriction of Operations within the Bounds of a Memory Buffer in joncampbell123 doslib
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in joncampbell123 doslib.This issue affects doslib: before doslib-20250729.
7.8
CVE-2026-33850 - Out-of-bounds Write in WujekFoliarz DualSenseY-v2
Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.
9.1
CVE-2026-4753 - Out-of-bounds Read in slajerek RetroDebugger
Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
6.4
CVE-2026-4752 - Use After Free in No-Chicken Echo-Mate
Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.
5.3
CVE-2026-4751 - NULL Pointer Dereference in tmate-io tmate
NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.
9.1
CVE-2026-4750 - Out-of-bounds Read in fabiangreffrath woof
Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.
6.5
CVE-2026-4749 - NVD-CWE-noinfo in albfan miraclecast
NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.
7.5
CVE-2026-4662 - JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass secuβ¦
9.1
CVE-2026-4283 - WP DSGVO Tools (GDPR) <= 3.1.38 - Missing Authorization to Unauthenticated Account Destruction of Nβ¦
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmβ¦