24h | 7d | 30d

Overview

  • buildwps
  • PPWP – Password Protect Pages

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.75%

KEV

Description

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Pending

30 Mar 2026
Published
26 May 2026
Updated

CVSS
Pending
EPSS
8.55%

KEV

Description

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK, and PPPoE credentials. In some observed cases, configuration changes may also be performed without authentication.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Drupal
  • Drupal core

20 May 2026
Published
23 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
88.32%

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • OnGres
  • StackGres

23 Aug 2026
Published
23 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.48%

KEV

Description

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Pending

06 May 2026
Published
26 May 2026
Updated

CVSS
Pending
EPSS
24.68%

KEV

Description

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authentication bypass and network compromise. Some firmware versions may expose only partial identifiers (e.g., serial number, ESSID, MAC addresses).

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
  • 0
  • 0
  • 0
  • 4h ago
Showing 21 to 25 of 25 CVEs