Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-56854 — Source-address critical option not enforced for non-public-key auth callbacks in golang.o…

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE…

| Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-4378 — Stored XSS in Akıllı Ticaret's E-Commerce Pack

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects …

Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-82330 — Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validat…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated dat…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.4 HIGH
CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.4 HIGH
CVE-2026-81019 — wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record with…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-82220 — WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-81767 — WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81761 — WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81760 — WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14…

jetengine | Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-81759 — WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.2 HIGH
CVE-2026-81757 — WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81299 — WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulner…

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-81285 — WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service At…

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

smush_image_compression_and_optimization | Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81284 — WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.5 HIGH
CVE-2026-82227 — WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

wpbulky | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-82328 — Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect vali…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.5 MEDIUM
CVE-2026-82327 — Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from v…

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache f…

Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-5953 — Reflected XSS in Ceviz Informatics's Web Design

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 2…

Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-5800 — Reflected XSS in Dayneks Software's E-Commerce Platform

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue af…

Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12538 Results