Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 9 August 2026
RSS234 vulnerabilities published on 9 August 2026
Severity:
Shenzhen Aitemi M300 Wi-Fi Repeater allows remote command execution
CVE-2026-19348
A security flaw in the Shenzhen Aitemi M300 Wi-Fi Repeater allows hackers to remotely take control of the device. This could happen if an attacker sends the device a malicious message. We recommend th...
8.9
InfiniteWP Client WordPress Plugin: Administrator Account Hijacking on Multisite
CVE-2026-15038
A security issue affects InfiniteWP Client, a WordPress plugin used for managing multiple sites. If not addressed, an attacker could gain control of an entire network of sites, allowing them to execut...
9.8
MSI Radix AXE6600 Router Firmware v781521 Command Injection Risk
CVE-2026-71993
An attacker can execute commands on your MSI Radix AXE6600 router, gaining control over the device. This is a serious security risk because an attacker could use this to access your network and sensit...
9.3
MSI Radix AXE6600 Router Telnet Configuration Hack
CVE-2026-71991
The MSI Radix AXE6600 router's firmware has a security flaw in its Telnet configuration. This flaw allows hackers to remotely take control of the router's settings and potentially gain full access to ...
9.3
MSI Radix AXE6600 Router Firmware v781521 Allows Remote Command Execution
CVE-2026-71988
The MSI Radix AXE6600 router's firmware has a security flaw that lets hackers send commands to the device from anywhere. This can allow them to take control of the router and access sensitive informat...
9.3
MSI Radix AXE6600 Router Firmware v781521 Allows Remote Command Execution
CVE-2026-71986
A vulnerability in the dmz function of MSI Radix AXE6600 router firmware v781521 allows attackers to execute commands on the router. This could lead to unauthorized access to the router and its settin...
9.3
WP Directory Kit Plugin SQL Injection Risk
CVE-2026-18473
The WP Directory Kit plugin for WordPress is vulnerable to SQL injection attacks if an attacker knows the right input. This could allow them to access or modify sensitive data. Update the plugin to ve...
9.1
Tenda CH22: Remote Command Injection via Form Submission
CVE-2026-19346
A vulnerability in the Tenda CH22 router's form submission feature allows attackers to inject malicious commands, potentially leading to unauthorized access or data tampering. This issue affects the d...
7.4
UTT HiPER 1200GW pptpSrvGlobalConfig Buffer Overflow Risk
CVE-2026-19341
The UTT HiPER 1200GW router has a security flaw that could be exploited by a hacker to execute malicious code remotely. This could allow them to access or control your router, which could lead to unau...
7.4
WordPress File Upload Plugin - Unauthenticated SQL Injection
CVE-2026-17044
The WordPress File Upload plugin, used in some websites, has a security flaw that could allow hackers to access sensitive data without a password. This affects sites using an outdated version of the p...
8.6
rootio-perl: Unauthorized access to sensitive data
ROOT-OS-DEBIAN-12-CVE-2023-31486
CVE-2023-31486
DEBIAN-CVE-2023-31486
UBUNTU-CVE-2023-31486
The rootio-perl package, used in Root:Debian:12, had a security issue that allowed unauthorized access to sensitive data. Root has released a patch to fix this issue, and you should update your packag...
8.1
CubeWP Framework SQL Injection via Unchecked User Access
CVE-2026-17017
The CubeWP Framework plugin for WordPress has a security flaw that could allow attackers to manipulate database queries, potentially leading to unauthorized access or data tampering. This affects all ...
8.1
Red Hat Hardened Images RPMs Updated to Fix Security Issues
RHSA-2026:42986
Red Hat Hardened Images RPMs have been updated to address security issues and improve performance. This update affects systems using Red Hat Hardened Images RPMs. To stay secure, ensure your system is...
7.5
WP Maps Pro plugin < 6.1.3: Unauthenticated Denial of Service
CVE-2026-18464
An attacker can crash the server running the WP Maps Pro plugin on a WordPress site, making it unavailable to users. This can happen if the plugin is not updated to the latest version, which fixes thi...
7.5
WooCommerce Order Data Exposed via WPC Order Tip Plugin
CVE-2026-18357
An older version of the WPC Order Tip for WooCommerce plugin on a WordPress site allows hackers to access customer order information without a password. This could let attackers see sensitive details ...
7.5
WP Data Access < 5.5.79 - Unauthenticated Password Exposure
CVE-2026-18032
The WP Data Access plugin for WordPress allows unauthorized access to sensitive user data, including passwords, when using a specific form. This is a serious issue because attackers can potentially ga...
7.5
GeoDirectory plugin - Unauthenticated access to private listings
CVE-2026-16988
The GeoDirectory WordPress plugin for websites has a security issue that allows anyone to see private listings, including their exact location. This is a concern for businesses that use private listin...
7.5
Parisneo Lollms 2.1.0 allows unauthorized file access
CVE-2026-10595
An attacker can access any file on the server without permission, which could lead to sensitive information being exposed. This is a security risk because it allows unauthorized access to server files...
7.5
Perl Crypt::OpenSSL::PKCS12 versions before 1.98 can crash with a malicious file
CVE-2026-17510
DEBIAN-CVE-2026-17510
Perl's Crypt::OpenSSL::PKCS12 module is vulnerable to a crash when processing certain types of files. This issue affects users who process untrusted PKCS#12 files. To protect against this issue, updat...
7.5
libexpat Denial of Service via XML Input
JLSEC-2026-1223
A denial of service attack can occur when libexpat processes a large, specially crafted XML file. This can happen if you're using a version of libexpat older than 2.8.1. To protect yourself, update to...
7.5
adafap api-mcp Server-Side Request Forgery via Custom API Endpoint
CVE-2026-19374
An attacker can trick adafap api-mcp into making unauthorized requests on behalf of the server, potentially leading to data breaches or other security issues. This affects the Proxy API Endpoint compo...
5.5
MingSoft MCMS SQL Injection via Malformed Form Data
CVE-2026-19355
A security flaw in MingSoft MCMS allows attackers to inject malicious SQL code into the system, potentially allowing them to access sensitive data. This vulnerability affects versions up to 3.0.6. It'...
5.5
dresende node-sql-query SQL Injection via Request Parameter
CVE-2026-19351
A security issue in dresende node-sql-query allows attackers to inject malicious SQL code. This could lead to unauthorized data access or manipulation. To fix this, update to version 0.1.29.
5.5
Vim for Linux: Arbitrary Code Execution Risk
RHSA-2026:38511
A security issue has been identified in the Vim text editor for Linux systems. If exploited, it could allow attackers to execute arbitrary code, potentially leading to unauthorized access or data thef...
7.3
Red Hat Vim Security Update: Unauthenticated Code Execution
RHSA-2026:38510
A security update is available for Red Hat's version of the Vim text editor. If left unpatched, an attacker could potentially execute malicious code on a vulnerable system without needing a password. ...
7.3