CVE-2026-94117Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.
2026-09-22 · score 7.6
CVE-2026-25264Privilege escalation due to weak configuration during package extraction process.
2026-09-22 · score 8.8
CVE-2026-25255Exposed dangerous function lead to privilege escalation via gRPC server.
2026-09-22 · score 8.8
CVE-2026-9231The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
2026-09-22 · score 7.5
CVE-2026-95511A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.
2026-09-22 · score 8.2