4.3
CVE-2026-2306 - Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creatiโฆ
The Ninja Tables โ Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subโฆ
6.5
CVE-2026-5753 - All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authenticated (Subscโฆ
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before savinโฆ
5.3
CVE-2026-3208 - Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Paymโฆ
The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieveโฆ
4.4
CVE-2026-7572 - Velociraptor EVTX Parser โ Process Crash via Crafted .evtx File
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx โฆ
5
CVE-2026-7573 - GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organiโฆ
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parโฆ
7.5
CVE-2025-71256 - Remote Denial of Service via Improper Input Validation in Unisoc NR Modem
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
7.5
CVE-2025-71255 - Remote Denial of Service via Improper Input Validation in Unisoc Modem IMS
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
7.5
CVE-2025-71254 - Improper Input Validation in Modem IMS Leading to Remote Denial of Service
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
7.5
CVE-2025-71253 - Improper Input Validation in Modem IMS Leading to Remote Denial of Service
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
7.5
CVE-2025-71252 -
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.