Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-14213 — Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any e…

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-14182 — Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover vi…

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can sa…

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-13610 — KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privilege…

kivicare | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-13328 — TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only …

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.4 MEDIUM
CVE-2026-72506 — NICT VoiceTra Improper Resource Identification Vulnerability

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be direct…

| Misconfiguration
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-19182 — OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge a…

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as …

horizon meridian | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.4 MEDIUM
CVE-2026-19135 — OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary c…

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that esc…

horizon meridian | Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-18728 — Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker o…

enterprise_linux enterprise_linux | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
1.7 LOW
CVE-2026-0301 — PAN-OS: Information Disclosure Vulnerability in URL Filtering

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panor…

pan-os prisma_access pan-os prisma_access prisma_access pan-os +2 more | Remote | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.9 MEDIUM
CVE-2026-0299 — GlobalProtect App: Local Privilege Escalation Vulnerabilities

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.2 MEDIUM
CVE-2026-0298 — GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLA…

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.2 MEDIUM
CVE-2026-0297 — GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially exe…

globalprotect_app globalprotect_app | Memory Corruption
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.5 MEDIUM
CVE-2026-0296 — GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application co…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.1 MEDIUM
CVE-2026-0295 — GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.0 MEDIUM
CVE-2026-0294 — Prisma Access Agent: Local Privilege Escalation

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma A…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.6 MEDIUM
CVE-2026-0293 — Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to prot…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
2.1 LOW
CVE-2026-0292 — Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing t…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
1.1 LOW
CVE-2026-0291 — Prisma Access Agent: Authenticated Limited File Deletion on Linux

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files i…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0290 — Prisma Browser: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

prisma_browser prisma_browser | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0289 — Prisma Browser: Inappropriate Implementation in Account Protection

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

prisma_browser prisma_browser | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 11084 Results