Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-14206 — HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
4.8 MEDIUM
CVE-2026-13701 — Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-13600 — AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-…

Remote | Authentication
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-13170 — Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include an…

Remote | Path Traversal
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.4 HIGH
CVE-2026-13133 — LINE for Windows DLL Hijacking Vulnerability

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious…

line | Misconfiguration
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
2.2 LOW
CVE-2026-12971 — LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featu…

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arb…

learnpress | Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.5 MEDIUM
CVE-2026-12570 — Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.…

keras | Denial of Service
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
Showing 20 of 14287 Results