Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19454 — JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site wh…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19225 — Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Multisite

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19223 — Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary c…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16569 — ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation th…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16568 — ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried t…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16567 — Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Token Oracle

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrar…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13416 — CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has gra…

| Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13415 — CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_impo…

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13414 — CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via c…

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on other…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81491 — boxpositron with-context-mcp index.ts project_folder path traversal

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation c…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.1 MEDIUM
CVE-2026-16895 — Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) …

| Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.5 MEDIUM
CVE-2026-81486 — bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a mani…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.5 MEDIUM
CVE-2026-81485 — danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path tr…

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the c…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.8 MEDIUM
CVE-2026-19398 — ASUS BIOS SmiFlash Out-of-Bounds Write Vulnerability

“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a c…

| Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81421 — ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint re…

sentry-selfhosted-mcp | Remote | Server-Side Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-80183 — OpenStack Keystone Authorization Bypass Vulnerability

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.i…

keystone | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-47874 — Reactor Netty HTTP Server Denial of Service With Pipelined Requests

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 …

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.9 MEDIUM
CVE-2026-47863 — Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream del…

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-47862 — ZipTransformer uses file_name header to build workDirectory path without sanitization

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem…

spring_integration | Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.3 MEDIUM
CVE-2026-47861 — UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when a…

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or exter…

spring_integration | Remote | Server-Side Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12256 Results