Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.0 MEDIUM
CVE-2026-90502 — stilleshan ServerStatus Stats Generation main.cpp cross site scripting

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the ar…

serverstatus | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90501 — lenve vhr HrMapper.xml HrInfoController.updateHr privileges management

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password le…

vhr | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90500 — lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the…

vhr | Remote | Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90499 — lenve vhr Password Update pass HrInfoController.updatePass improper authorization

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of…

vhr | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90498 — lenve vhr vhr.sql default credentials

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploi…

vhr | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.0 MEDIUM
CVE-2026-90497 — Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Tas…

feng_office | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.8 MEDIUM
CVE-2026-90496 — Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order s…

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.cla…

feng_office | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-89080 — Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demo…

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who alread…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-88995 — Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve o…

Remote | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.2 MEDIUM
CVE-2026-88912 — rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity P…

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a no…

rtmedia | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.4 MEDIUM
CVE-2026-88764 — Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard s…

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, all…

simple_membership | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.7 LOW
CVE-2026-86407 — User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Members…

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any regi…

Remote | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-86406 — User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership …

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitte…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.7 MEDIUM
CVE-2026-80072 — User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect…

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitor…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.2 HIGH
CVE-2026-80071 — User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authe…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-77773 — Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure…

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthentica…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-90679 — Forgejo ActivityPub Identity Spoofing Vulnerability

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not…

forgejo | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90678 — HAProxy HTTP Request Smuggling Vulnerability

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC b…

haproxy | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90495 — Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the compone…

feng_office | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90494 — restify node-restify static.js serveStatic path traversal

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be ini…

node-restify | Remote | Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13129 Results