Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-94158 — WordPress Gloria Admin Panel plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admi…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-93947 — WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a thr…

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-78341 — Dell Secure Connect Gateway Incorrect Authorization Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Authorization vulnerability. A high privileged attacker with remote access could potentially expl…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-78340 — Dell Secure Connect Gateway Path Traversal Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privil…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-78339 — Dell Secure Connect Gateway Incorrect Permission Assignment Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local a…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.8 MEDIUM
CVE-2026-78027 — Dell Secure Connect Gateway Server-Side Request Forgery

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potent…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-78026 — Dell Secure Connect Gateway Authorization Bypass

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote acces…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-78025 — Dell Secure Connect Gateway Policy Manager Missing Authentication Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access c…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-78024 — Dell Secure Connect Gateway Server-Side Request Forgery Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potent…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-78023 — Dell Secure Connect Gateway Authorization Bypass

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote acces…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-71884 — Packet CTR reports a full success length after the counter is exhausted

In Bouncy Castle for Java LTS before 2.73.13, the native one-shot CTR packet cipher did not check that the requested input length fitted the counter space the IV left. In CTR mode the IV and the bloc…

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-62049 — WordPress JetBlocks For Elementor plugin <= 1.5.2.1 - Cross Site Scripting (XSS) vulnerab…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For …

jetblocks_for_elementor | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-107935 — Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host vi…

A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the call…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.1 MEDIUM
CVE-2026-84224 — Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL

The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to intern…

Remote | Server-Side Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.8 MEDIUM
CVE-2026-84220 — Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection

The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing un…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.8 MEDIUM
CVE-2026-78022 — Dell Secure Connect Gateway Policy Manager Protection Mechanism Bypass

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could pote…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.7 LOW
CVE-2026-78021 — Dell Secure Connect Gateway Information Disclosure Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-78020 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potenti…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-78019 — Dell Secure Connect Gateway Inclusion of Functionality from Untrusted Control Sphere Vuln…

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remo…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-78018 — Dell Secure Connect Gateway Initialization of a Resource with an Insecure Default Vulnera…

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A low privileged attacker with local a…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14189 Results