Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-8151 — Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF

The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the confi…

Remote | Cross-Site Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.8 MEDIUM
CVE-2026-83547 — Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets

The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role a…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-83533 — WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment

The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a comp…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.0 CRITICAL
CVE-2026-82955 — Eclipse aeriOS KrakenD JWT Validation Security Bypass

In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard…

Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.8 MEDIUM
CVE-2026-82884 — All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block

The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor …

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-82293 — Kibana Incorrect Authorization Vulnerability

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180)…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.8 MEDIUM
CVE-2026-81571 — Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM Param…

The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have ar…

Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-79991 — Authenticated SQL Injection via nested eager-loading criteria

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces sit…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-79990 — GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/…

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces sit…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-79989 — Arbitrary user password reset leading to administrator account takeover

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other u…

cms | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-78609 — Elastic Cloud on Kubernetes Incorrect Authorization Vulnerability

Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.8 HIGH
CVE-2026-78604 — Elastic Agent Incorrect Permission Assignment Privilege Escalation

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is ins…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-78602 — Elastic Maps Server Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated at…

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-78601 — Kibana Missing Authorization Vulnerability

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.5 LOW
CVE-2026-78600 — Elastic Cloud on Kubernetes Incomplete Cleanup Privilege Escalation

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace associati…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-78599 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAP…

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-78598 — Kibana Machine Learning Incorrect Authorization Vulnerability

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authen…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.9 MEDIUM
CVE-2026-78594 — Elastic APM Server Improper Handling of Highly Compressed Data Denial of Service

Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source …

Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.3 MEDIUM
CVE-2026-78591 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). …

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.3 HIGH
CVE-2026-78590 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (C…

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12585 Results