Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-91086 — GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. …

| Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-90711 — proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet writ…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91004 — SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument I…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-91003 — D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes s…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-91002 — stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipula…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.9 CRITICAL
CVE-2026-91001 — D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument se…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
2.5 LOW
CVE-2026-86701 — ManabiPocket for Parents Improper Access Control Vulnerability

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit t…

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-81320 — Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM …

| Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.3 MEDIUM
CVE-2026-81303 — Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostna…

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource direc…

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-18232 — WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowi…

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated a…

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.9 MEDIUM
CVE-2026-17495 — moment vulnerable to Path Traversal via crafted non-string locale name

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can…

| Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-16593 — WP Directory Kit <= 1.5.7 - Editor+ SQL Injection via Elementor Category and Location Wid…

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builde…

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-16592 — WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via Shortcod…

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-publi…

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.3 MEDIUM
CVE-2026-15758 — 3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' Parameter

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the …

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-91005 — SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php mo…

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture …

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-75983 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authen…

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the …

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-15402 — Eventin <= 4.1.23 - Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_…

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter …

| Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-89141 — AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sens…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' para…

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-90881 — D-Link DIR-882 CGI Binary dllog.cgi main information disclosure

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to informati…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.4 HIGH
CVE-2026-90880 — D-Link DSL-3782 Diagnostics Diagnostics.asp system command injection

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a m…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 12956 Results