Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CVE-2026-1255 - YS LeadGen – Popups, Opt-ins & Lead Capture = 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action

CVE ID : CVE-2026-1255 Published : Sept. 19, 2026, 9:16 a. m. • 11 hours, 40 minutes ago Description : The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2. 1. 4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms. Severity: 7.5 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

Three HP Easy Start Vulnerabilities Expose macOS Systems to Root-Level Attacks

Three high-severity vulnerabilities in HP Easy Start for macOS could enable local attackers and, in limited scenarios, network-positioned adversaries to interfere with printer software installation workflows and modify files through a privileged execution path. Tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, the flaws were identified by Nir Yehoshua of Cipher Security Labs during an assessment of HP Easy Start version 2. 16. 0. HP addressed the issues in version 2. 16. 7. 260722 under a security bulletin. CVE-2026-12555 is the most direct local privilege-related issue. The flaw affects the HP Easy Start Uninstaller, which used predictable, world-writable file locations in /tmp and /private/tmp after the user approved an administrative elevation prompt.

·CyberPress
Read →

You've reached the end of current stories for this search.