2026-09-07 Daily Vulns
NEW:
| CVE | vendor-product | description | metric | Referenceurl | title | GithubURL | |
|---|---|---|---|---|---|---|---|
| CVE-2025-15693 | Unknown - JCH Optimize | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root. | CNA n/a CVSS3.1: 2.7 - LOW | 0 | Exploitation: noneAutomatable: noTechnical Impact: partial | JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal | github |
| CVE-2021-44320 | n/a - n/a | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding. | CNA n/a CVSS3.1: 7.5 - HIGH | 0 1 2 | Exploitation: noneAutomatable: yesTechnical Impact: partial | undefined | github |
This post is licensed under CC BY 4.0 by the author.