Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-66602 — WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forge…

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a …

Remote | Cross-Site Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-66603 — WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-21584 — Atlassian Bamboo Data Center Improper Authorization Vulnerability

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerabil…

bamboo_data_center | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-21582 — Atlassian Crowd Data Center Broken Authentication and Session Management Vulnerability

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & …

| Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-21580 — Atlassian Confluence Data Center and Server Stored Cross-Site Scripting, Privilege Escala…

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.…

confluence_server confluence_data_center | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-53959 — 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authen…

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrie…

| Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-53958 — 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEm…

| Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-50186 — 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-50191 — 4gaBoards: Pre-Account Takeover via SSO Email Linkage

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEn…

| Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52854 — mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser funct…

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts atta…

| Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52875 — Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a ren…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52876 — Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled …

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52873 — Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electr…

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:w…

| Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52877 — Streambert : Insecure Protocol Execution in open-external IPC Handler

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url …

| Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-52872 — Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IP…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-15316 — Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertex…

tapo_c200 | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-15315 — Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link…

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter vali…

tapo_c200 | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-47699 — Confidential Containers Guest Components image-rs: zip-slip-class arbitrary file write vi…

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpac…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-62377 — libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF…

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequenc…

| Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-62291 — libheif: Heap out of bounds write in libheif uncompressed encoder when writing images wit…

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled …

| Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 12276 Results