Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-76561 — Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile co…

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile …

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-71374 — Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from …

cosminexus_component_container | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.2 HIGH
CVE-2026-81806 — WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerab…

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-48888 — WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

woocommerce | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-81781 — WordPress Unbounce Landing Pages plugin <= 1.1.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: fr…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-81790 — WordPress Csomagpontok és szállítási címkék WooCommerce-hez plugin < 4.2.8 - Broken Acces…

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csoma…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-81798 — WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4…

Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84818 — WordPress Open User Map plugin <= 1.4.50 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

open_user_map | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84817 — WordPress JetFormBuilder plugin <= 3.6.5.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

jetformbuilder | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-81802 — WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerabil…

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privi…

Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84820 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86519 — code-projects Student Crud Operation Backup File card_activation.sql information disclosu…

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results…

Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86518 — code-projects Student Crud Operation edit.php sql injection

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The att…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86517 — itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument I…

sales_and_inventory_system | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script githu…

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component …

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.0 MEDIUM
CVE-2026-86515 — vgmstream txtp txtp_parser.c add_entry resource consumption

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument ran…

Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-86514 — vgmstream txth-txtp txth.c sscanf stack-based overflow

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer ove…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86513 — java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokens…

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/json…

jackson-coreutils | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply ac…

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOpera…

json-patch | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12502 Results