Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-82330 — Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validat…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-82328 — Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect vali…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.5 MEDIUM
CVE-2026-82327 — Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from v…

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache f…

Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-82324 — Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles case…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.5 HIGH
CVE-2026-82227 — WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

wpbulky | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-82220 — WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.5 MEDIUM
CVE-2026-82181 — Le-yan|Medical Practice Management System - Sensitive Data in URL

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log…

| Information Disclosure
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.1 MEDIUM
CVE-2026-82112 — houtini-ai houtini-lm code_task_files index.ts path traversal

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead t…

Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.4 CRITICAL
CVE-2026-82078 — PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable dr…

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-81767 — WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81761 — WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81760 — WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14…

jetengine | Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-81759 — WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.2 HIGH
CVE-2026-81757 — WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative fun…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated dat…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81299 — WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulner…

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-81285 — WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service At…

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

smush_image_compression_and_optimization | Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-81284 — WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.4 HIGH
CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12503 Results