Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-45124 — MyBB: Mod CP report resolution missing authorization

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark report…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-45123 — MyBB: IPv6 SSRF

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The defau…

Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-45122 — MyBB: Insufficient permission check for calendar event move

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation perm…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-45121 — MyBB: Insufficient permission check for calendar select

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of cale…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-45120 — MyBB: Insufficient authorization for private calendar events

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access a…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.6 MEDIUM
CVE-2026-45119 — MyBB: ACP UTF-8 Conversion CSRF

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding a…

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-45118 — MyBB: Contact page reflected XSS

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code in…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.8 CRITICAL
CVE-2026-45117 — MyBB: Installer database configuration RCE

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, res…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-45116 — MyBB: Profile field type confusion XSS

MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injecti…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-45115 — MyBB: Buddy/ignore list username XSS

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a speci…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-19501 — CVE-2026-19501

CSV export functionality in Brainstorm Force SureForms version, <= 2.1.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which a…

| Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-19500 — SureForms contains an uncontrolled resource consumption vulnerability

The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, whi…

| Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.0 MEDIUM
CVE-2026-15806 — `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme m…

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when match…

cpython cpython | Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.6 CRITICAL
CVE-2026-12564 — Automation-controller: automation-controller: kubernetes service account token exfiltrati…

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service accou…

ansible_automation_platform | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.5 HIGH
CVE-2026-75898 — RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canv…

ragflow | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-75872 — HTML Injection in MailerUp double opt-in verification email

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
10.0 CRITICAL
CVE-2026-75784 — TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipula…

tew-wlc100 | Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.3 MEDIUM
CVE-2026-75032 — Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetoot…

enterprise_linux enterprise_linux | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-74015 — WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-74012 — WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability

Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 11258 Results