Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-47849 — Spring Data REST allows mutation of identifier and version properties via JSON Patch

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data …

spring_data_rest | Remote | Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19715 — WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug …

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing un…

| Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19454 — JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site wh…

jetbackup | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19225 — Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Multisite

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute…

defender_security | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-19223 — Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary c…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16569 — ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation th…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16568 — ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried t…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-16567 — Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Token Oracle

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrar…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13416 — CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has gra…

cmp | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13415 — CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_impo…

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has…

cmp | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-13414 — CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via c…

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on other…

cmp | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81491 — boxpositron with-context-mcp index.ts project_folder path traversal

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation c…

with-context-mcp | Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.1 MEDIUM
CVE-2026-16895 — Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) …

| Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.5 MEDIUM
CVE-2026-81486 — bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a mani…

mcp-file-context-server | Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.5 MEDIUM
CVE-2026-81485 — danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path tr…

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the c…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.8 MEDIUM
CVE-2026-19398 — ASUS BIOS SmiFlash Out-of-Bounds Write Vulnerability

“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a c…

fa507nv fa507nu | Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81421 — ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint re…

sentry-selfhosted-mcp | Remote | Server-Side Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-80183 — OpenStack Keystone Authorization Bypass Vulnerability

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.i…

keystone | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-47874 — Reactor Netty HTTP Server Denial of Service With Pipelined Requests

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 …

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.9 MEDIUM
CVE-2026-47863 — Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream del…

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12220 Results