24h | 7d | 30d

Overview

  • wptravelengine
  • WP Travel Engine – Tour Booking Plugin – Tour Operator Software

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.58%

KEV

Description

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-9231: LFI in WP Travel Engine WordPress plugin (up to 6.8.0), CVSS 7.5. Contributors can include and execute arbitrary PHP files. No patch yet - disable plugin or restrict access. valtersit.com/cve/CVE-2026-923 #CVE #WordPress #infosec

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-95511 CUPS priv esc, CVSS 8.2. lpadmin user can abuse the serial backend to write arbitrary files as root, leading to root RCE. Note: this CVE was REJECTED/WITHDRAWN - verify before acting. Details: valtersit.com/cve/CVE-2026-955 #CVE #infosec #CUPS

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • PostgreSQL

13 Aug 2026
Published
29 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.56%

KEV

Description

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

A critical PostgreSQL RCE vulnerability allows remote code execution. Details and PoC for this PostgreSQL RCE vulnerability are now public. Update now.

securityonline.info/postgresql

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • WatchGuard
  • WatchGuard AP

28 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

WatchGuard patched critical WatchGuard AP vulnerabilities allowing OS command injection. Update your access points to version 3.4.8 to prevent attacks.

securityonline.info/watchguard

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • WatchGuard
  • WatchGuard AP

28 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
Pending

KEV

Description

An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

WatchGuard patched critical WatchGuard AP vulnerabilities allowing OS command injection. Update your access points to version 3.4.8 to prevent attacks.

securityonline.info/watchguard

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • WatchGuard
  • WatchGuard AP

28 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

WatchGuard patched critical WatchGuard AP vulnerabilities allowing OS command injection. Update your access points to version 3.4.8 to prevent attacks.

securityonline.info/watchguard

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • wolfSSL
  • wolfSSL

27 Sep 2026
Published
27 Sep 2026
Updated

CVSS v4.0
HIGH (8.3)
EPSS
0.29%

KEV

Description

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is also defined this widens the affected API to include all CA certificate loading. Both macros are defined when using autoconf builds such as (nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, ffmpeg, all, distro). When the certificate is listed as a trusted peer certificate the issue previously allowed for a malicious (D)TLS server to bypass authentication once knowing which CA’s the client would accept. This also affects mutual authentication cases where the client knows which CA’s the server has loaded. If building with any of these configurations and using (D)TLS where the loaded CA’s could be known and authentication of the peer is desired, users should either: update to the latest wolfSSL version, apply the fix patch, or use the configure flag --disable-openssl-compatible-defaults and not load CA’s with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert() to mitigate the issue.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

wolfSSL 5.9.4 patches 10 wolfSSL vulnerabilities, including TLS authentication bypass flaws CVE-2026-93302 and CVE-2026-89136. Upgrade now.

securityonline.info/wolfssl-5-

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Esri patched three Portal for ArcGIS vulnerabilities, including CVE-2026-69227. Apply Security Update 4 to secure your enterprise GIS environment today.

securityonline.info/portal-for

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Esri patched three Portal for ArcGIS vulnerabilities, including CVE-2026-69227. Apply Security Update 4 to secure your enterprise GIS environment today.

securityonline.info/portal-for

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • wolfSSL
  • wolfSSL

27 Sep 2026
Published
27 Sep 2026
Updated

CVSS v4.0
HIGH (8.3)
EPSS
0.55%

KEV

Description

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

wolfSSL 5.9.4 patches 10 wolfSSL vulnerabilities, including TLS authentication bypass flaws CVE-2026-93302 and CVE-2026-89136. Upgrade now.

securityonline.info/wolfssl-5-

  • 0
  • 0
  • 0
  • 4h ago
Showing 41 to 50 of 62 CVEs