|
1531
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
The ChipIdea UDC driver can encounter "not page aligned sg buffer"
error…
|
-
|
CVE-2026-43250
|
2026-05-6 22:07 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1532
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: cx88: Add missing unmap in snd_cx88_hw_params()
In error path, add cx88_alsa_dma_unmap() to release
resource acquired by c…
|
-
|
CVE-2026-43257
|
2026-05-6 22:07 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1533
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: in-kernel: always set ID as avail when rm endp
Syzkaller managed to find a combination of actions that was generating
…
|
-
|
CVE-2026-43252
|
2026-05-6 22:07 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1534
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all ver…
|
CWE-862
Missing Authorization
|
CVE-2026-3208
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1535
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::s…
|
CWE-862
Missing Authorization
|
CVE-2026-5753
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1536
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in al…
|
CWE-862
Missing Authorization
|
CVE-2026-2306
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1537
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNo…
|
CWE-22
Path Traversal
|
CVE-2026-6344
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1538
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6672
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1539
|
7.5 |
HIGH
Network
|
-
|
-
|
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of su…
|
CWE-89
SQL Injection
|
CVE-2026-1719
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1540
|
7.2 |
HIGH
Network
|
-
|
-
|
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2026-7332
|
2026-05-6 22:06 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|