Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-86170 — DefaultFuction CRM edit.php sql injection

A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-86171 — DefaultFuction CRM delete.php sql injection

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql inje…

| Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-85038 — B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrat…

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one a…

| Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-84219 — Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then r…

| Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-84028 — Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_setti…

The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to…

| Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-75793 — SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a…

| Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-18480 — SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level …

| Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-13159 — Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation

The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set…

| Cross-Site Request Forgery
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86168 — code-projects Content Management System login.php sql injection

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name resu…

content_management_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.9 CRITICAL
CVE-2026-86167 — Tenda HG10 Boa formgponConf os command injection

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loi…

hg10 | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.0 HIGH
CVE-2026-86166 — Tenda HG10 Boa Web Server formWanRedirect buffer overflow

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation …

hg10 | Remote | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
10.0 HIGH
CVE-2026-86165 — Tenda HG10 formURL buffer overflow

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results …

hg10 | Remote | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-86164 — itsourcecode Sales and Inventory System trans_view.php sql injection

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in s…

sales_and_inventory_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-86163 — itsourcecode Sales and Inventory System pro_del.php sql injection

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql inject…

sales_and_inventory_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
10.0 CRITICAL
CVE-2026-86218 — pre-authentication remote code execution

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

n-central | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86162 — SourceCodester Online Voting System ajax.php login sql injection

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can l…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86161 — SourceCodester Online Voting System ajax.php delete_category sql injection

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argume…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86160 — SourceCodester Online Voting System ajax.php delete_voting sql injection

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86159 — SourceCodester Online Voting System ajax.php save_user sql injection

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. Th…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.8 CRITICAL
CVE-2026-75816 — Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_obje…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value fun…

Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
Showing 20 of 12411 Results