CVEs
| Date | CVE | Product | Impact | CVSS |
|---|---|---|---|---|
| 2026-10 | CVE-2026-107181 | Telegram Desktop | Arbitrary file read, takeover | 8.1 |
| 2026-07 | CVE-2026-49243 | Webmin | XSS to root command execution | 9.6 |
| 2026-06 | reserved | under embargo | Disclosure not permitted | — |
| 2025-11 | CVE-2025-11749 | WordPress AI Engine | Token exposure, admin escalation | 9.8 |
| 2024-12 | CVE-2024-11768 | WordPress Download Manager | Unauth. download of protected files | 5.3 |
| 2024-11 | CVE-2024-10499 | WordPress AI Engine | SQL injection via REST API | 4.9 |
| 2024-09 | CVE-2024-8031 | WordPress Secure Downloads | Arbitrary file read as admin | 4.9 |
Acknowledgments
- Trend Micro — Vulnerability Response, disclosures for 2022