CVE-2026-16895
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC...

2026-08-27T17:17:17.653

7.3 CVE-2026-81491
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder...

2026-08-27T17:20:54.450

4.8 CVE-2026-13414
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions...

2026-08-27T17:17:08.830

7.2 CVE-2026-13415
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings...

2026-08-27T17:17:09.330

3.5 CVE-2026-13416
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting...

2026-08-27T17:17:09.820

5.3 CVE-2026-16567
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing...

2026-08-27T17:17:15.080

4.3 CVE-2026-16568
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin...

2026-08-27T17:17:15.567

4.3 CVE-2026-16569
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin...

2026-08-27T17:17:16.060

7.2 CVE-2026-19223
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators,...

2026-08-27T17:17:35.027

6.6 CVE-2026-19225
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network...

2026-08-27T17:17:35.610

4.4 CVE-2026-19454
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before...

2026-08-27T17:17:38.330

7.5 CVE-2026-19715
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access...

2026-08-27T17:17:42.513

7.1 CVE-2026-47849
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation...

2026-08-27T17:18:28.120

6.4 CVE-2026-47864
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream...

2026-08-27T13:18:18.253

5.6 CVE-2026-47875
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable...

2026-08-27T13:18:18.840

8.2 CVE-2026-47877
Spring Security Authorization Server's default consent page renders user-controlled values without HTML...

2026-08-27T17:18:33.537

5.6 CVE-2026-47878
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded...

2026-08-27T17:18:33.987

7.7 CVE-2026-47879
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining...

2026-08-27T17:18:34.440

5.4 CVE-2026-47880
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component...

2026-08-27T17:18:34.887

5.9 CVE-2026-47881
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical...

2026-08-27T17:18:35.367

6.1 CVE-2026-47883
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns....

2026-08-27T17:18:35.863