Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.6 LOW
CVE-2026-101094 — Affinity Heap Buffer Over-Read

The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buf…

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.9 MEDIUM
CVE-2026-96396 — Affinity Heap-Based Buffer Overflow Vulnerability

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity docu…

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.6 LOW
CVE-2026-96395 — Affinity for macOS Heap-based Out-of-Bounds Read

The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
2.9 LOW
CVE-2026-96394 — Affinity Out-of-Bounds Heap Read Vulnerability

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.6 LOW
CVE-2026-96393 — Affinity Out-of-Bounds Pointer Dereference

The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-85531 — Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This …

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.8 MEDIUM
CVE-2026-89235 — Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter

The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to …

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-87846 — Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion

The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyo…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-86851 — Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection &…

The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticat…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-85348 — GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF

The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they …

Remote | Cross-Site Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-62042 — WordPress Scripts n Styles plugin <= 3.5.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: …

scripts_n_styles | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-62041 — WordPress WP Event Manager plugin <= 3.4.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-62040 — WordPress Restrict User Access – Membership plugin with Force plugin <= 2.8.1 - Broken Ac…

Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force restrict-user-access allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-62039 — WordPress Html5 Audio Player plugin <= 2.8.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio P…

html5_audio_player | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-62036 — WordPress All Bootstrap Blocks plugin <= 1.3.31 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in AREOI All Bootstrap Blocks all-bootstrap-blocks allows Retrieve Embedded Sensitive Data.This issue affects …

all_bootstrap_blocks | Remote | Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-39779 — WordPress Asgaros Forum plugin <= 3.4.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-107419 — WordPress AI Translation for Polylang plugin <= 1.6.2 - Broken Access Control vulnerabili…

Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-103329 — Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signat…

The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by …

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-62028 — WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Brok…

Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Lev…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.5 HIGH
CVE-2026-8374 — Misuse and Misconfiguration of Cryptographic Algorithm in Bluetooth Communication

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

| Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14188 Results