CVE-2026-42208
BerriAI LiteLLM SQL Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Sunday's disclosures center on WordPress plugin vulnerabilities, with multiple critical flaws affecting MStore API, Plugin Download, and TheCartPress carrying CVSS 9.8 ratings. The day brought 8 critical CVEs (down 71% from Saturday's 28) and 65 high-priority vulnerabilities (down 35% from 100). Notable disclosures include CVE-2021-47933 in WordPress MStore API, CVE-2021-47923 affecting OpenCart, and CVE-2026-44313 in Arch Linkwarden, all rated 9.1 or higher. Attack patterns concentrate on web application infrastructure and OAuth2 library implementations, with HP enterprise applications also represented. Patch availability sits at 0% across yesterday's disclosures, requiring defenders to rely on workarounds and compensating controls until vendor fixes arrive.
Immediate action: Prioritize WordPress administrators reviewing affected plugins (MStore API, Plugin Download, TheCartPress) and consider disabling vulnerable extensions until patches are released. Organizations running ConnectWise ScreenConnect, BerriAI LiteLLM, or recent Linux Kernel and Windows builds should verify exposure given confirmed active exploitation, while OpenCart and Linkwarden operators should apply available compensating controls given the 0% patch availability.
BerriAI LiteLLM SQL Injection Vulnerability - Active in CISA KEV catalog.
ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability - Active in CISA KEV catalog.
An arbitrary file upload vulnerability in the MStore API allows unauthenticated attackers to execute malicious code on the host server via the REST API.
An arbitrary file upload vulnerability in the Plugin Download WordPress plugin allows unauthenticated attackers to upload and execute malicious files via the admin-ajax.php endpoint.
A remote code execution vulnerability in OpenCATS allows unauthenticated attackers to execute arbitrary system commands by uploading malicious PHP files as resume attachments.
An unauthenticated privilege escalation vulnerability in TheCartPress WordPress plugin allows attackers to create new administrative accounts via the AJAX handler.
A critical vulnerability in phpVMS allows unauthenticated access to a legacy import feature, potentially exposing application data or functionality.
A session fixation vulnerability in OpenCart allows attackers to hijack user sessions by forcing the use of a known, malicious session identifier.
A Server-Side Request Forgery (SSRF) vulnerability in Linkwarden allows authenticated users to make unauthorized requests to internal services via insufficient URL validation.
A flaw in the Patreon OAuth provider mapping causes multiple distinct user accounts to be incorrectly merged into a single local identity, leading to potential account takeovers.
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PHPUnit is a testing framework for PHP
ipl/web is a set of common web components for php projects
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript
PraisonAI is a multi-agent teams system
WordPress Plugin Survey & Poll 1
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2
AzuraCast is a self-hosted, all-in-one web radio management suite
e107 CMS 2
ImpressCMS 1
Evolution CMS 3
TextPattern CMS 4
Aero CMS 0
PraisonAI multi-agent teams system contains an unspecified security vulnerability requiring immediate investigation.
pygeoapi is a Python server implementation of the OGC API suite of standards
pyp2spec generates working Fedora RPM spec file for Python projects
Plainpad is a self hosted note taking app
Argo Workflows contains a high-severity vulnerability that could impact the security of container-native job orchestration on Kubernetes.
pygeoapi is a Python server implementation of the OGC API suite of standards
Brave CMS is an open-source CMS
The Avo framework for Ruby on Rails admin panels contains a security vulnerability that could impact administrative access controls.
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
Russh is a Rust SSH client & server library
Opencart TMD Vendor System 3
Balbooa Joomla Forms Builder 2
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary
New API, an LLM gateway and AI asset management system, contains an unspecified vulnerability that may impact system security.
Postiz AI social media scheduling tool contains a security vulnerability that could lead to unauthorized access or service disruption.
Insufficient input validation in the cPanel Nova plugin's `create_user` function allows for arbitrary Perl code execution.
A symlink vulnerability in the cPanel Nova plugin's `Cpanel::Nova::Connector` allows for unauthorized modification of system file permissions.
A security vulnerability has been detected in EFM ipTIME A8004T 14
Sentry 8
CyberPanel 2
Brave CMS is an open-source CMS
i18next-http-middleware is a middleware to be used with Node
18next-http-middleware is a middleware to be used with Node
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
nanoMODBUS through v1
i18next-fs-backend is a backend layer for i18next using in Node
i18next-http-middleware is a middleware to be used with Node
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge
OmniFaces is a utility library for Faces
An issue exists in Amazon Redshift JDBC Driver versions prior to 2
MailEnable Enterprise Premium 10
The SCRAM code in PgBouncer before 1
AzuraCast is a self-hosted, all-in-one web radio management suite
Cilium is a networking, observability, and security solution with an eBPF-based dataplane
Argus Surveillance DVR 4
FastGPT is an AI Agent building platform
An issue in fohrloop dash-uploader v
ZEBRA is a Zcash node written entirely in Rust
ZEBRA is a Zcash node written entirely in Rust
An issue was discovered in kosma minmea 0
lwjson 1
locize is a localization platform that connects code and i18n setup
Crypt::PasswdMD5 versions through 1
An integer overflow in network packet parsing code in PgBouncer before 1
apko allows users to build and publish OCI container images built from apk packages
apko allows users to build and publish OCI container images built from apk packages
memono Notepad 4
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8