stemshop.bsky.social
banner
stemshop.bsky.social
stemshop.bsky.social
@stemshop.bsky.social
Critical CVEs, vulnerability research, PoCs and security intelligence. Tracking high-impact vulnerabilities and affected products.

https://stemshop.top/cve/
#CVE #CyberSecurity #InfoSec #Vulnerability #SecurityResearch
🚨 CVE-2026-82901 — CVSS 9.8 CRITICAL

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insu...

🔎 https://stemshop.top/cve/CVE-2026-82901

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 8:08 PM
🚨 CVE-2026-85984 — CVSS 9.8 CRITICAL

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authenti...

🔎 https://stemshop.top/cve/CVE-2026-85984

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 8:07 PM
🚨 CVE-2026-97163 — CVSS 10 CRITICAL

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0,...

🔎 https://stemshop.top/cve/CVE-2026-97163

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:08 PM
🚨 CVE-2026-97161 — CVSS 9.2 CRITICAL

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5....

🔎 https://stemshop.top/cve/CVE-2026-97161

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:08 PM
🚨 CVE-2026-97160 — CVSS 9.4 CRITICAL

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0...

🔎 https://stemshop.top/cve/CVE-2026-97160

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:08 PM
🚨 CVE-2026-94132 — CVSS 9.5 CRITICAL

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMai...

🔎 https://stemshop.top/cve/CVE-2026-94132

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:08 PM
🚨 CVE-2026-94130 — CVSS 9.3 CRITICAL

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An...

🔎 https://stemshop.top/cve/CVE-2026-94130

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:08 PM
🚨 CVE-2026-100720 — CVSS 9.3 CRITICAL

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-priv...

🔎 https://stemshop.top/cve/CVE-2026-100720

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100716 — CVSS 9.4 CRITICAL

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDum...

🔎 https://stemshop.top/cve/CVE-2026-100716

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100714 — CVSS 9.4 CRITICAL

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibli...

🔎 https://stemshop.top/cve/CVE-2026-100714

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100706 — CVSS 9.4 CRITICAL

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allow...

🔎 https://stemshop.top/cve/CVE-2026-100706

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100684 — CVSS 9.2 CRITICAL

Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budi...

🔎 https://stemshop.top/cve/CVE-2026-100684

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100607 — CVSS 9.2 CRITICAL

Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or sub...

🔎 https://stemshop.top/cve/CVE-2026-100607

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-100606 — CVSS 9.2 CRITICAL

Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the ...

🔎 https://stemshop.top/cve/CVE-2026-100606

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 4:07 PM
🚨 CVE-2026-18143 — CVSS 9.8 CRITICAL

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all vers...

🔎 https://stemshop.top/cve/CVE-2026-18143

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 8:07 AM
🚨 CVE-2026-100382 — CVSS 10 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in...

🔎 https://stemshop.top/cve/CVE-2026-100382

#CVE #CyberSecurity #InfoSec
September 26, 2026 at 12:07 AM
🚨 CVE-2026-100390 — CVSS 9.1 CRITICAL

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when sett...

🔎 https://stemshop.top/cve/CVE-2026-100390

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 10:07 PM
🚨 CVE-2026-100389 — CVSS 9.2 CRITICAL

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's ...

🔎 https://stemshop.top/cve/CVE-2026-100389

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 10:07 PM
🚨 CVE-2026-97064 — CVSS 9.3 CRITICAL

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by def...

🔎 https://stemshop.top/cve/CVE-2026-97064

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 8:08 PM
🚨 CVE-2026-97063 — CVSS 9.3 CRITICAL

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints ...

🔎 https://stemshop.top/cve/CVE-2026-97063

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 8:07 PM
🚨 CVE-2026-84458 — CVSS 9.1 CRITICAL

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic acc...

🔎 https://stemshop.top/cve/CVE-2026-84458

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 8:07 PM
🚨 CVE-2026-48482 — CVSS 9.4 CRITICAL

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can...

🔎 https://stemshop.top/cve/CVE-2026-48482

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 8:07 PM
🚨 CVE-2026-92161 — CVSS 9.8 CRITICAL

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers....

🔎 https://stemshop.top/cve/CVE-2026-92161

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 6:07 PM
🚨 CVE-2026-62262 — CVSS 9.1 CRITICAL

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, wh...

🔎 https://stemshop.top/cve/CVE-2026-62262

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 6:07 PM
🚨 CVE-2026-42322 — CVSS 9.1 CRITICAL

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_...

🔎 https://stemshop.top/cve/CVE-2026-42322

#CVE #CyberSecurity #InfoSec
September 25, 2026 at 6:07 PM