Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-1771 — MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/s…

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an i…

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-1372 — Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+…

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_…

tutor_lms_elementor_addons | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.7 MEDIUM
CVE-2026-15370 — Libssh: libssh: stack buffer overflow in sftp server longname construction

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list a…

Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.4 MEDIUM
CVE-2026-15145 — Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including…

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.3 MEDIUM
CVE-2026-8593 — Fix Business Intelligence API Pack permission

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs an…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.1 HIGH
CVE-2026-3183 — Multi Factor Auth Bypass

Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.

manageengine_adselfservice_plus | Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-8082 — Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers…

| Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-14185 — WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-leve…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-14184 — Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via ID…

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level a…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-14183 — Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscrib…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-13694 — Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's …

| Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-13693 — Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attacke…

| Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-11767 — CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthent…

| Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-3182 — Sensitive Data Exposure

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

manageengine_endpoint_central | Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.0 MEDIUM
CVE-2026-16266 — mongo-object Prototype Pollution Vulnerability

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a c…

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.8 MEDIUM
CVE-2026-15927 — Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url val…

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, …

quay mirror_registry_for_red_hat_openshift | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.8 MEDIUM
CVE-2026-15812 — Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dyna…

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting …

Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.8 MEDIUM
CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration…

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes t…

Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.9 MEDIUM
CVE-2026-15782 — WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMo…

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration dat…

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-13439 — Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Admi…

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password r…

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8285 Results