Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 2 June 2026

RSS

32 vulnerabilities published on 2 June 2026

Severity:
Kirki WordPress Plugin Allows Unwanted Account Access
CVE-2026-8206
The Kirki plugin for WordPress allows attackers to take control of any account on a website. This can happen if an attacker knows the username of a registered user. To fix this, update the Kirki plugi...
9.8
CVE-2026-48962 in rootio-perl - Patched by Root
ROOT-OS-DEBIAN-12-CVE-2026-48962
Root has patched CVE-2026-48962 in the rootio-perl package for Root:Debian:12. Multiple fixed versions available.
7.8
MLflow with Basic Auth Fails to Enforce Authorization Checks
CVE-2026-3198
MLflow 3.9.0 with basic authentication has a security issue where it doesn't properly check permissions for certain sensitive information. This allows any authenticated user to see API keys, endpoint ...
6.5
Zyxel VMG4005-B50B Router: Temporary Denial-of-Service Risk
CVE-2026-3871
A flaw in the router's firmware allows a nearby attacker to temporarily shut down the UPnP feature, disrupting internet connectivity. This affects devices connected to the router that rely on UPnP. Us...
6.5
Zyxel VMG4005-B50B UPnP Buffer Overflow: Temporary Service Disruption
CVE-2026-3870
A flaw in the Zyxel VMG4005-B50B router's UPnP feature allows an attacker on the same network to temporarily shut down the router's UPnP service. This could cause issues with devices relying on UPnP f...
6.5
WordPress plugin allows malicious scripts in image metadata
CVE-2026-3722
The Auto Image Attributes plugin for WordPress has a security flaw that allows attackers with certain permissions to inject malicious code into image metadata. This could potentially allow them to exe...
6.4
DedeCMS download feature allows server to be tricked
CVE-2026-10581
A security issue affects the download feature in DedeCMS version 5.7.88. This issue allows an attacker to trick the server into making unauthorized requests, potentially leading to further security is...
2.1
itsourcecode Fees Management System 1.0 SQL Injection via ID Parameter
CVE-2026-10568
The itsourcecode Fees Management System 1.0 contains a security flaw that allows an attacker to access sensitive data by manipulating the ID parameter in the /manage_payment.php file. This could lead ...
2.1
SourceCodester Pizzafy Ecommerce System 1.0 File Inclusion Risk
CVE-2026-10559
An unknown function in the SourceCodester Pizzafy Ecommerce System 1.0 allows attackers to include unauthorized files, potentially leading to sensitive information exposure or malicious code execution...
2.1
SourceCodester Pizzafy Ecommerce System: Remote File Inclusion Risk
CVE-2026-10558
The Pizzafy Ecommerce System, version 1.0, has a security flaw that allows an attacker to access and include unauthorized files on a website. This could potentially allow an attacker to access sensiti...
2.1
Elunez Eladmin 2.7 Allows Remote Code Execution
CVE-2026-10550
An unknown issue in Elunez Eladmin's Application Deployment Module could allow attackers to execute malicious code remotely. This could happen if an attacker exploits a publicly available exploit. We ...
2.1
itsourcecode Fees Management System 1.0 SQL Injection Risk
CVE-2026-10302
The itsourcecode Fees Management System 1.0 has a security flaw that makes it possible for attackers to manipulate data. This could lead to unauthorized access to sensitive information. We recommend u...
2.1
MetaGPT 0.8.2: Unrestricted Input Can Cause Code Execution
CVE-2026-10566
A security flaw in MetaGPT's message checking function allows an attacker to execute code on a local system. This could be exploited by anyone with access to the affected version of MetaGPT, and a pub...
1.9
NousResearch hermes-agent Credential Pool Authentication Bypass
CVE-2026-10548
A security issue in NousResearch hermes-agent allows an attacker with local access to bypass authentication checks. This could potentially allow unauthorized access to sensitive data. NousResearch has...
1.9
Nextlevelbuilder GoClaw TTS Config Data Exposure Risk
CVE-2026-10583
A vulnerability in Nextlevelbuilder GoClaw version 3.11.3 or earlier allows attackers to trick the server into making unauthorized requests. This could potentially expose sensitive data or disrupt the...
2.0
Simple Custom Login Page plugin for WordPress: Unauthorized CSS Injection
CVE-2026-10100
The Simple Custom Login Page plugin for WordPress versions up to 1.0.3 allows attackers to inject malicious CSS code into the login page, which can be used to trick visitors into revealing their login...
4.4
Slider Revolution plugin for WordPress allows unauthorized plugin deactivation
CVE-2026-9050
The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 allows an attacker with a Contributor-level account or above to deactivate any active plugin on the site. This coul...
4.3
Slider Revolution plugin for WordPress exposes sensitive data
CVE-2026-9048
The Slider Revolution plugin for WordPress, used in versions 7.0.0 to 7.0.14, allows attackers with Contributor-level access to access sensitive information like social media passwords and API keys. T...
4.3
itsourcecode Fees Management System 1.0 allows Remote Code Execution
CVE-2026-10301
A security issue in itsourcecode Fees Management System 1.0 could allow an attacker to execute malicious code on your website. This could happen if a user visits a malicious website or clicks on a lin...
2.1
CordysCRM Save Function Cross-Site Scripting Risk
CVE-2026-10567
A security risk has been found in the Save function of CordysCRM, which allows an attacker to inject malicious code. This could happen if an attacker sends a specially crafted request to the system. T...
2.0
Orthanc DICOM Server: Local Buffer Overflow Risk
CVE-2026-10528
A security flaw in Orthanc DICOM Server allows an attacker with local access to potentially cause harm by overflowing a buffer. This issue affects versions up to 1.12.11, and a patch is available to f...
1.9
Open5GS NGAP Handover Allows Remote Attack
CVE-2026-10565
A security issue in Open5GS's NGAP Handover component allows a remote attacker to potentially exploit a weakness in the system. This could allow an attacker to access or disrupt the system, but the at...
1.3
CicadasCMS Task Scheduling Management Module Cross-Site Scripting
CVE-2026-10529
A weakness in CicadasCMS's Task Scheduling Management Module can allow an attacker to inject malicious code into the system. This could potentially allow them to take control of the system or steal us...
1.9
1Panel-dev CordysCRM up to 1.6.2 allows malicious website code execution
CVE-2026-10514
An unknown function in 1Panel-dev CordysCRM allows attackers to inject malicious code into a website, potentially leading to unauthorized actions. This issue affects versions 1.6.2 and earlier. To fix...
1.9
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a us...
CVE-2026-8293
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user'...