Logo
  • NEWS
  • NVD
  • EXPLOITS
  • SECURITY
    • NCSC
    • SECURELIST
    • US-CERT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

  • Why Do So Many Apps Ask for Phone Number Verification?

    For users, it may feel like one more registration step. For app developers and businesses, however, phone verification solves several …

    16 August 2026
    Apps, Ask, Mobile, Resources, Verification
  • CVE-2026-9767 – The The School Management – Education & Learning ERP plugin for WordPress is vulnerable …

    The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via ‘order[0][dir]’ …

    16 August 2026
    NVD
  • CVE-2026-2283 – The User Login History plugin for WordPress is vulnerable to SQL Injection via the …

    The User Login History plugin for WordPress is vulnerable to SQL Injection via the ‘blog_id’ parameter in all versions up to, and …

    16 August 2026
    NVD
  • CVE-2026-19934 – A vulnerability has been found in itsourcecode Hospital Management System 1.0. This …

    A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. …

    16 August 2026
    NVD
  • CVE-2026-19728 – The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does …

    The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a …

    16 August 2026
    NVD
  • CVE-2026-19726 – The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the …

    The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with …

    16 August 2026
    NVD
  • CVE-2026-19725 – The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not …

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request …

    16 August 2026
    NVD
  • CVE-2026-19717 – The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have …

    The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API …

    16 August 2026
    NVD
  • CVE-2026-19714 – The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the …

    The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing …

    16 August 2026
    NVD
  • CVE-2026-19712 – The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz …

    The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants …

    16 August 2026
    NVD
  • CVE-2026-19711 – The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal …

    The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user’s actual earned …

    16 August 2026
    NVD
  • CVE-2026-19613 – The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks …

    The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources …

    16 August 2026
    NVD
{"loadingDistance":1200,"stickyPosts":[],"nextPageLink":"https://itts.at/page/2","queryId":0}

●●●

CookieFree

NVD

  • CVE-2026-9767 – The The School Management – Education & Learning ERP plugin for WordPress is vulnerable …16 August 2026
  • CVE-2026-19920 – A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is …16 August 2026
  • CVE-2026-19921 – A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by …16 August 2026
  • CVE-2026-19919 – A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an …16 August 2026
  • CVE-2026-19918 – A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This …16 August 2026

EXPLOITS

  • LuCI DHCPv6 – Lease Hostname Stored Cross-Site Scripting11 August 2026
  • mcp-server-kubernetes 3.8.x – Argument Injection11 August 2026
  • PraisonAI praisonaiagents 1.6.77 – Remote Code Execution11 August 2026
  • Apache Gravitino 1.2.1 – SSRF11 August 2026
  • Blocksy Companion 2.1.46 – RCE11 August 2026

SECURELIST

  • APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit14 August 2026
  • Armored Likho expands its cyber-espionage toolkit13 August 2026
  • Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver Pha11 August 2026
  • Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectio11 August 2026
  • IT threat evolution in Q2 2026. Mobile statistics10 August 2026


Copyright © 2026 ITTS | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.