Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-12230 — LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lay…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to,…

learnpress | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
6.1 MEDIUM
CVE-2026-77654 — Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with …

| Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-19614 — XML External Entity (XXE) Injection in CyberELF NanoXML

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

Remote | XML External Entity
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-9331 — EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrar…

The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpe…

Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-86590 — Eclipse Che Server-Side Request Forgery

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host f…

che | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitr…

typo3 | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-77132 — TYPO3 CMS - Information Disclosure via Backend Localization Wizard

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access inf…

typo3 | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86597 — Sensitive information written to logs by Snowflake drivers

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-s…

snowflake_connector | Information Disclosure
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-86550 — UXSS vulnerability in ZTE browser products

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑sit…

Remote | Cross-Site Scripting
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
6.8 MEDIUM
CVE-2026-74859 — Gnome-tweaks: path traversal in theme installer

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using …

Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-71377 — Command Argument Injection Vulnerability in Cosminexus Component Container

Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 t…

cosminexus_component_container | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-71376 — OS Command Injection Vulnerability in Cosminexus Component Container

OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through…

cosminexus_component_container | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.2 CRITICAL
CVE-2026-67367 — SIMOVE Fleetmanager and SIPLANT Directory Traversal Vulnerability

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fl…

Remote | Path Traversal
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
7.0 HIGH
CVE-2026-62654 — Reyrolle 7SR5 Unsigned Code Execution Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads …

| Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.0 HIGH
CVE-2026-62653 — Reyrolle 7SR5 Memory Corruption Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firm…

| Memory Corruption
Sep 08, 2026 Sep 14, 2026
Sep 08, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-62652 — Reyrolle 7SR5 Information Disclosure Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthentica…

Remote | Information Disclosure
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-62650 — Reyrolle 7SR5 Privilege Escalation Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based acce…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-62649 — Reyrolle 7SR5 Denial of Service Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP request…

Remote | Denial of Service
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
8.7 HIGH
CVE-2026-62648 — Reyrolle 7SR5 Out-of-Bounds Write Denial-of-Service Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending ad…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-62647 — Reyrolle 7SR5 Insufficiently Random Values Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authenticatio…

Remote | Authentication
Sep 08, 2026 Sep 14, 2026
Sep 08, 2026
Sep 14, 2026
Showing 20 of 15565 Results