CVE Security News

Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.

A CVE (Common Vulnerabilities and Exposures) entry is the standardized identifier assigned to a publicly disclosed security flaw, letting researchers, vendors and defenders reference the same vulnerability unambiguously. This feed tracks freshly published CVE IDs as they are assigned and disclosed — often the first public signal that a product needs patching. Coverage spans everything from obscure library bugs to critical remote-code-execution flaws in widely deployed software.

Recent CVE items

CVE-2026-86180 A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Log…
@cveNotify · Sep 6, 2026
CVE-2026-86179 A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler.…
@cveNotify · Sep 6, 2026
CVE-2026-86172 A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID result…
@cveNotify · Sep 6, 2026
CVE-2026-86171 A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID lea…
@cveNotify · Sep 6, 2026
CVE-2026-85038 The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registr…
@cveNotify · Sep 6, 2026
CVE-2026-84219 The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment…
@cveNotify · Sep 6, 2026
CVE-2026-84028 The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor rol…
@cveNotify · Sep 6, 2026
CVE-2026-75793 The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account…
@cveNotify · Sep 6, 2026
CVE-2026-18480 The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subs…
@cveNotify · Sep 6, 2026
CVE-2026-13159 The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to insta…
@cveNotify · Sep 6, 2026
CVE-2026-86170 A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes…
@cveNotify · Sep 6, 2026
CVE-2026-86168 A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument…
@cveNotify · Sep 6, 2026
CVE-2026-86167 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argum…
@cveNotify · Sep 6, 2026
CVE-2025-7195 Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_…
@cveNotify · Sep 6, 2026
CVE-2026-86166 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a…
@cveNotify · Sep 6, 2026
CVE-2026-86165 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/ur…
@cveNotify · Sep 6, 2026
CVE-2026-86164 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument I…
@cveNotify · Sep 6, 2026
CVE-2026-86163 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads…
@cveNotify · Sep 6, 2026
CVE-2026-2100 A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism…
@cveNotify · Sep 6, 2026
CVE-2025-7425 A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result…
@cveNotify · Sep 6, 2026
CVE-2025-49796 A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicio…
@cveNotify · Sep 6, 2026
CVE-2025-49794 A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw…
@cveNotify · Sep 6, 2026
CVE-2025-5914 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultim…
@cveNotify · Sep 6, 2026
CVE-2025-5278 A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user…
@cveNotify · Sep 6, 2026
CVE-2026-86218 N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. 🎖
@cveNotify · Sep 6, 2026
CVE-2026-86162 A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument…
@cveNotify · Sep 6, 2026
CVE-2026-86161 A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation…
@cveNotify · Sep 6, 2026
CVE-2026-86160 A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of t…
@cveNotify · Sep 6, 2026
CVE-2026-86159 A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql…
@cveNotify · Sep 6, 2026
CVE-2026-75816 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_up…
@cveNotify · Sep 6, 2026

Other topics

Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.