Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-57331 — WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerabi…

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

Remote | Path Traversal
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
10.0 CRITICAL
CVE-2026-56290 — Joomlack Page Builder Improper Access Control Vulnerability - [Actively Exploited]

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

page_builder_ck | CISA KEV Remote | Authentication
Jun 29, 2026 Jul 08, 2026
Jun 29, 2026
Jul 08, 2026
9.8 CRITICAL
CVE-2026-49048 — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for…

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or …

joomcck | Remote | Injection
Jun 28, 2026 Jun 30, 2026
Jun 28, 2026
Jun 30, 2026
9.9 CRITICAL
CVE-2026-58053 — Gitea act_runner - Container Hardening Bypass via Workflow Container Options

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, force…

Remote | Misconfiguration
Jun 28, 2026 Jun 30, 2026
Jun 28, 2026
Jun 30, 2026
9.8 CRITICAL
CVE-2026-12415 — Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover vi…

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1…

Remote | Authorization
Jun 27, 2026 Jun 29, 2026
Jun 27, 2026
Jun 29, 2026
9.8 CRITICAL
CVE-2026-31928 — Daktronics Controller Firmware Use of Hard-coded Credentials

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using the…

Jun 26, 2026 Jul 06, 2026
Jun 26, 2026
Jul 06, 2026
9.8 CRITICAL
CVE-2026-28701 — Daktronics Controller Firmware Path Traversal

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

Jun 26, 2026 Jul 06, 2026
Jun 26, 2026
Jul 06, 2026
10.0 CRITICAL
CVE-2026-53576 — Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /co…

kestra | Remote | Authentication
Jun 26, 2026 Jul 01, 2026
Jun 26, 2026
Jul 01, 2026
10.0 CRITICAL
CVE-2026-49869 — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authenticatio…

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public confi…

kestra | Remote | Authentication
Jun 26, 2026 Jul 01, 2026
Jun 26, 2026
Jul 01, 2026
9.6 CRITICAL
CVE-2026-54352 — Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip…

budibase | Remote | Path Traversal
Jun 26, 2026 Jun 30, 2026
Jun 26, 2026
Jun 30, 2026
9.6 CRITICAL
CVE-2026-54351 — Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution …

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution paramete…

budibase | Remote | Authentication
Jun 26, 2026 Jun 30, 2026
Jun 26, 2026
Jun 30, 2026
10.0 CRITICAL
CVE-2026-54350 — Budibase: Anonymous NoSQL operator injection via published-app query templates

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB…

budibase | Remote | Injection
Jun 26, 2026 Jun 30, 2026
Jun 26, 2026
Jun 30, 2026
9.4 CRITICAL
CVE-2026-50137 — Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous c…

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint…

budibase | Remote | Misconfiguration
Jun 26, 2026 Jun 30, 2026
Jun 26, 2026
Jun 30, 2026
9.8 CRITICAL
CVE-2026-53309 — ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead o…

linux_kernel | Remote | Memory Corruption
Jun 26, 2026 Jul 06, 2026
Jun 26, 2026
Jul 06, 2026
9.9 CRITICAL
CVE-2026-52785 — OpenProject: SQL injection in timestamps functionality

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to …

openproject | Remote | Injection
Jun 26, 2026 Jun 29, 2026
Jun 26, 2026
Jun 29, 2026
9.9 CRITICAL
CVE-2026-52782 — OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH par…

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages…

openproject | Remote | Authorization
Jun 26, 2026 Jun 29, 2026
Jun 26, 2026
Jun 29, 2026
9.6 CRITICAL
CVE-2026-52780 — OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17…

openproject | Misconfiguration
Jun 26, 2026 Jun 27, 2026
Jun 26, 2026
Jun 27, 2026
9.9 CRITICAL
CVE-2026-46386 — OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `…

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key.…

openproject | Remote | Cryptography
Jun 26, 2026 Jun 29, 2026
Jun 26, 2026
Jun 29, 2026
9.6 CRITICAL
CVE-2026-33646 — mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function regis…

mise | Remote | Misconfiguration
Jun 26, 2026 Jun 29, 2026
Jun 26, 2026
Jun 29, 2026
9.9 CRITICAL
CVE-2026-54636 — Dokku: OS Command Injection via app.json managed Cron

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special she…

dokku | Remote | Injection
Jun 26, 2026 Jun 29, 2026
Jun 26, 2026
Jun 29, 2026
Showing 20 of 949 Results