Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-81625 — Stack buffer overflow in Greenbone OS and openvas-scanner

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromi…

Remote | Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81581 — User input in WibuKey is used (without proper sanitization) to compute the address of a p…

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually resu…

| Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81579 — An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileg…

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabli…

| Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.7 HIGH
CVE-2026-81576 — Improper Authentication of Session Handles

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force…

Remote | Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81575 — Missing Sanity Checks for Buffer Lengths

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data l…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.2 HIGH
CVE-2026-81574 — Format String Vulnerability in Logger

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to re…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81573 — Improper Access Control in Local-Only Configuration Commands

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network …

Remote | Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.8 HIGH
CVE-2026-81572 — Local Privilege Escalation in CodeMeter Runtime on Windows

cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic link…

| Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-81279 — WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken Access Contro…

Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.5 HIGH
CVE-2026-81277 — WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerability

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-81276 — WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-81274 — WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

ditty | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.1 HIGH
CVE-2026-81273 — WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerabi…

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

Remote | Cross-Site Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
4.9 MEDIUM
CVE-2026-81272 — WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81271 — WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

Remote | Cross-Site Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-80433 — WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure vulnerabili…

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-78293 — WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.8 CRITICAL
CVE-2026-78292 — WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

hash_form | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-78289 — WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-78288 — WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability

Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12236 Results