Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-12477 — Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting via 'styler…

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insuffi…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-11780 — Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site S…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2025-10005 — Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authentic…

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the pp…

password_protect_wordpress | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.4 MEDIUM
CVE-2026-2487 — Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting …

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and outp…

admin_custom_login | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19930 — Dolibarr User Cloning card.php ldap injection

A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID resul…

dolibarr | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19929 — OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elemen…

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the compon…

openboxes | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19928 — OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interc…

openboxes | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19927 — OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request for…

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component …

openboxes | Remote | Server-Side Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-19926 — Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF…

evergreen | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.8 MEDIUM
CVE-2026-19925 — SourceCodester Stock Management System Master.php delete_supplier sql injection

A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argum…

stock_management_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
10.0 HIGH
CVE-2026-19924 — Tenda AC10 httpd R7WebsSecurityHandler improper authentication

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to impro…

ac10_firmware ac10 | Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19923 — code-projects Online Shopping System checkout_process.php sql injection

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can le…

online_shopping_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.0 MEDIUM
CVE-2026-19922 — code-projects Online Shopping System checkout.php cross site scripting

A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argum…

online_shopping_system | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19921 — code-projects Online Shopping System homeaction.php sql injection

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument c…

online_shopping_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19920 — code-projects Online Shopping System action.php sql injection

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It i…

online_shopping_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-19919 — code-projects Online Shopping System Login login.php sql injection

A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results i…

online_shopping_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.3 MEDIUM
CVE-2026-19918 — SpaceX Starlink Router Gen 3 gRPC Management get_status access control

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to imprope…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19917 — code-projects Online Food Order System delete_food_items1.php sql injection

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox …

online_food_order_system | Remote | Injection
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
8.7 HIGH
CVE-2026-74767 — Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed…

Remote | Denial of Service
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
10.0 CRITICAL
CVE-2026-74764 — Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's ta…

Remote | Path Traversal
Aug 15, 2026 Aug 15, 2026
Aug 15, 2026
Aug 15, 2026
Showing 20 of 11259 Results