Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-59671 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.5 MEDIUM
CVE-2026-95512 — Freetype: freetype: denial of service via repeated subroutine allocations in cid font loa…

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.4 HIGH
CVE-2026-80443 — Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Pl…

Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1.

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-59670 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-80337 — Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform

Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.9 MEDIUM
CVE-2026-80464 — API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform

Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1.

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-59669 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-91784 — Argument Injection leading to arbitrary process termination in gotop

cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process…

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-97663 — Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting…

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input …

customer_reviews_for_woocommerce | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-97641 — Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitizat…

relevanssi | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-97637 — JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_…

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the re…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-97634 — Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via…

The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on…

event_tickets | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-97342 — JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post…

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and incl…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.4 MEDIUM
CVE-2026-97338 — Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via …

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output …

download_manager | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-97336 — CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output es…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-96871 — Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Paramet…

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and o…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.4 MEDIUM
CVE-2026-96647 — Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authentic…

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up to, and inclu…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-96578 — GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficien…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-96567 — MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter…

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and out…

mw_wp_form | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-96566 — Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field …

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due …

newsletter | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14906 Results