Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 29 August 2026
RSS433 vulnerabilities published on 29 August 2026
Severity:
Argo CD MCP 0.8.0 lets anyone on network control system
CVE-2026-82456
Version 0.8.0 of Argo CD’s management component listens on all network addresses and, when a security token is set, does not verify who is connecting. Anyone who can reach the server can use that toke...
10.0
WooCommerce registration plugin lets attackers become admin
CVE-2026-15369
The Custom User Registration Fields for WooCommerce plugin (versions up to 2.2.3) lets anyone who can place an order assign themselves any user role, including Administrator. This happens because the ...
9.8
Cloud Commander allows reading or changing any file
CVE-2026-82460
The Cloud Commander web tool (versions before 19.20.2) does not correctly check file paths sent to its REST and markdown features. Because of this, a malicious user could trick the system into reading...
9.3
rust-iot-platform allows anyone to manage user accounts via its API
CVE-2026-82452
The rust-iot-platform software lets anyone send requests to most of its web API functions without needing to log in. As a result, an unauthenticated person could create, change, view, or delete user a...
9.3
Shinobi lets unauthenticated users run database queries
CVE-2026-82448
Versions of Shinobi released before the 5a76c74f code change contain a built‑in password that anyone can use to connect to the part of the system that talks to the database. An attacker who can reach ...
9.3
Sigma Forms Pro lets anyone upload files and run code
CVE-2026-14494
The Sigma Forms Pro add‑on for WordPress lets anyone on the internet send a file through its form fields, and the file can be placed on your server and executed as a program. This means an attacker co...
9.8
Uix UserCenter plugin can let attackers hijack admin accounts
CVE-2026-16259
The Uix UserCenter plugin for WordPress (through version 1.0.3) does not confirm that the person changing a profile actually owns that account, and it uses the same secret key for all installations. T...
9.8
MemberHero plugin lets anyone become admin
CVE-2026-10522
The MemberHero plugin for WordPress (versions up to 6.9) lets anyone submit a registration form and choose any user role, including Administrator. This can give strangers complete control of your site...
9.8
WordPress plugin lets attackers read files and write data
CVE-2026-77012
The 爱采集数据采集和发布插件 for WordPress (up to version 1.0.0) accepts requests without a unique secret and trusts any URL or file path it receives. This lets anyone on the internet read files on your server, m...
9.3
Omnivore API allows fake Apple sign‑in tokens
CVE-2026-82454
The Omnivore web service could be tricked into accepting a forged Apple login token, letting an attacker appear as any Apple‑linked user. This happens because the code used the token’s own settings to...
9.3
WooCommerce payment plugin can expose credentials and fake payments
CVE-2026-16947
The Total Payments plugin for WooCommerce (up to version 7.3) lets a remote user tell the system to contact any web address and does not check that the reply is genuine. This can leak the store's paym...
9.1
BookStack lets attackers run code via ZIP upload
CVE-2026-82450
Versions of BookStack released before 26.05.4 let people who can add books and import content place a specially crafted ZIP file that contains a hidden script. The script is saved where anyone on the ...
8.7
Skyvern versions before 1.0.45 allow code execution via text prompts
CVE-2026-82447
The Skyvern automation tool versions earlier than 1.0.45 let specially crafted text inputs run code on the server. This happens because the tool processes the same prompt twice, once in a safe mode an...
9.4
Rodauth login lets logged‑in users impersonate other accounts
CVE-2026-82466
DEBIAN-CVE-2026-82466
The Rodauth sign‑in feature allows a user who is already logged in to trick the system into acting as any other user. This happens because the software checks the wrong identifier when confirming a se...
9.4
OCaml cohttp package lets attackers access files outside intended folder
CVE-2026-82481
DEBIAN-CVE-2026-82481
The cohttp library used in OCaml applications can be tricked into reading or writing files outside the designated directory, which could expose sensitive data or allow unauthorized changes. Upgrade to...
8.7
WordPress Rest Routes plugin lets strangers run database commands
CVE-2026-16061
The Rest Routes plugin for WordPress (up to version 5.5.5) accepts data from a web address without checking it, then uses that data in a database query. This means anyone on the internet could trick t...
8.6
KubeEdge CloudCore lets anyone fake node upgrade results
CVE-2026-82473
The CloudCore component of KubeEdge (versions up to 1.23.1) accepts status reports about node upgrades without checking who sent them. An attacker who can reach the server on port 10002 could falsely ...
8.6
User Profile Builder lets anyone edit site content
CVE-2026-76548
The User Profile Builder plugin for WordPress (versions before 4.0.1) allows people who are not logged in to upload files and change media, posts, and pages that should be restricted. This could let s...
8.2
iFlytek Astron-Agent allows attackers to access or change other users' workflows
CVE-2026-82475
The Astron-Agent software up to version 1.1.1 does not verify that a user owns a workflow before allowing changes. As a result, a person who already has a login can view or overwrite other customers' ...
8.6
pac4j-core before 6.5.6 lets users skip login checks
CVE-2026-82463
The pac4j-core library versions earlier than 6.5.6 contain a mistake that flips the logic used to verify a user's role. Because of this, an attacker can log in with a low‑privilege account and still r...
8.6
pac4j-oidc versions before 6.5.6 allow forged tokens to gain admin rights
CVE-2026-82461
Applications that use the pac4j‑oidc library to read user roles from Keycloak may accept fake access tokens that look valid. Because the library does not check the token’s signature, issuer, audience,...
8.6
Sudo lets users run blocked programs on Linux
CVE-2026-82474
DEBIAN-CVE-2026-82474
On Linux systems, the sudo tool up to version 1.9.17p2 can be tricked to run programs that administrators have said should be blocked. This means a user who is supposed to run only certain approved co...
8.4
su-exec may run programs as root
CVE-2026-82457
The su-exec tool (versions up to 0.3) does not properly check large numeric user or group IDs, which can be reduced to zero and interpreted as the root account. This means a malicious user could cause...
8.4
SmartAIPress plugin lets logged-in users fetch any URL
CVE-2026-16600
The SmartAIPress plugin for WordPress (versions up to 1.2.0) lets anyone with a basic account tell the website to contact any web address and see the reply. This could expose internal systems or priva...
7.7
BOSH Director can be tricked to steal vCenter admin passwords
CVE-2026-41012
If someone can watch the network traffic between BOSH Director and vCenter, they can pretend to be vCenter and capture the administrator username and password. Those credentials give full control over...
7.7