Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-85534 — Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initi…

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicio…

enterprise_linux enterprise_linux | Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85512 — SourceCodester Class and Exam Timetabling System session.php authorization

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument I…

class_and_exam_timetabling_system | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-84428 — fastify vulnerable to header validation bypass via incomplete schema case normalization

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-84045 — E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation v…

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing un…

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-79707 — Arbitrary File Read in Google Agent Development Kit (ADK)

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary …

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.5 HIGH
CVE-2026-4644 — Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privilege…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-27347 — WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.

jetpopup | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.2 MEDIUM
CVE-2026-85547 — Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP

A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP'…

Remote | Cross-Site Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.6 HIGH
CVE-2026-85546 — MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuick…

Remote | Cross-Site Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-85541 — Interinfo|DreamMaker - Reflected Cross-site Scripting

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85540 — Interinfo|DreamMaker - SQL Injection

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.1 CRITICAL
CVE-2026-85184 — @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request tar…

@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request …

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.1 HIGH
CVE-2026-84504 — fastify vulnerable to request body replacement via an async validation result collision

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-84469 — fastify vulnerable to request validation bypass via skipped boolean false schemas

fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instan…

| Misconfiguration
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-84044 — Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged Pa…

The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a…

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-84043 — ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Byp…

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders …

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.8 CRITICAL
CVE-2026-82923 — AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugi…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-81666 — Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message…

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow i…

Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-76169 — fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-…

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler …

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-27086 — WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

woodmart | Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12546 Results