Current NIST Vulnerability Highlights

Current NIST Vulnerability Highlights

Updated by WordPress scheduled task. Last collected: 2026-09-04 16:16:29 UTC

CVE-2026-5800 MEDIUM 6.1
Published: 2026-08-28T16:18:19.533

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure…

CVE-2026-5096 MEDIUM 5.3
Published: 2026-08-28T16:18:18.820

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload…

CVE-2026-58107 MEDIUM 5.5
Published: 2026-08-28T16:18:18.293

CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte…

CVE-2026-58106 LOW 2
Published: 2026-08-28T16:18:18.137

CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r  was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed down is the full PATH_MAX. safe_strcpy() is strncpy(), which NUL-pads the destination out to the whole n, so this site writes 4096…

CVE-2026-56854 HIGH 7.5
Published: 2026-08-28T16:18:17.607

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not…

CVE-2026-50979 HIGH 8.1
Published: 2026-08-28T16:18:14.037

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

CVE-2026-4378 MEDIUM 5.4
Published: 2026-08-28T16:18:13.490

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.

CVE-2026-3423 MEDIUM 6.4
Published: 2026-08-28T16:17:56.640

The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, 1.12.4 due to insufficient input sanitization and output escaping. This makes it possible…

CVE-2026-38725 MEDIUM 5.4
Published: 2026-08-28T16:17:47.190

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates…

CVE-2026-38638 HIGH 7.5
Published: 2026-08-28T16:17:47.063

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

This product uses data provided by the National Institute of Standards and Technology (NIST) but is not endorsed or certified by NIST.