Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12128 — Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price…

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dop…

| Authorization
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15341 — User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Tak…

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function…

| Authentication
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15001 — bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privil…

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_co…

| Authentication
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15303 — 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registere…

| Authentication
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-8840 — Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthe…

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verify…

| Authorization
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15162 — Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection

The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's p…

| Injection
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15965 — MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parame…

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload func…

| Misconfiguration
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-15312 — Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) …

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's RE…

| Authorization
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-14484 — RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'fi…

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload functio…

| Path Traversal
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-16080 — Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection via Attachmen…

The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on t…

| Injection
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
0.0 NA
CVE-2026-14433 — Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated St…

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including,…

| Cross-Site Scripting
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
6.3 MEDIUM
CVE-2026-74250 — OpenStack Ironic Autodetect Deploy Interface Improper Cleaning Execution Vulnerability

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

ironic | Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.2 MEDIUM
CVE-2026-74247 — Quay: ssrf via build archive_url in quay build api

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allow…

openshift quay openshift | Remote | Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.9 MEDIUM
CVE-2026-74245 — Quay: unauthenticated exported logs download in quay

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex…

openshift quay openshift | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.9 MEDIUM
CVE-2026-74244 — Quay: stripe webhook accepts forged events without signature verification in quay

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/str…

openshift quay openshift | Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-74243 — Quay: unauthenticated secscan notification endpoint in quay when psk is unset

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint.…

openshift quay openshift | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-74242 — Quay: repository notification uuid idor in quay api

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, inc…

openshift quay openshift | Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.8 MEDIUM
CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly…

openshift quay openshift | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-74240 — Quay: jwt claim validation bypasses in quay federated robot and sso authentication

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enfor…

openshift quay openshift | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
2.0 LOW
CVE-2026-63650 — OpenVPN mbedTLS X.509 Identity Misidentification Vulnerability

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10593 Results