Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-2292 — Morkva UA Shipping <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting …

The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and outp…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-2289 — Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Bl…

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output esca…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-1980 — WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Expo…

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This…

wpbookit | Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1945 — WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and '…

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient …

wpbookit | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-1651 — Email Subscribers & Newsletters <= 5.9.16 - Authenticated (Administrator+) SQL Injection …

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping…

Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1273 — PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API …

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/…

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-3266 — Improper access control vulnerability has been discovered in OpenText™ Filr.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. …

filr | Remote | Authorization
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
10.0 CRITICAL
CVE-2026-28289 — FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with …

freescout | Remote | Misconfiguration
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.4 HIGH
CVE-2026-27981 — HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1…

homebox | Remote | Authentication
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27971 — Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user…

qwik | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-27932 — joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows…

joserfc | Remote | Denial of Service
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-27905 — BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path i…

bentoml | Path Traversal
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-27622 — OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals…

openexr | Memory Corruption
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.2 HIGH
CVE-2026-27601 — Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an …

underscore | Remote | Denial of Service
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
5.0 MEDIUM
CVE-2026-27600 — HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST req…

homebox | Remote | Server-Side Request Forgery
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2026-26279 — Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injec…

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields de…

froxlor | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
5.4 MEDIUM
CVE-2026-26272 — HomeBox affected by Stored XSS via HTML/SVG Attachment Upload

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does n…

homebox | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2026-26266 — AliasVault affected by Cross-Site Scripting (XSS) via Email HTML Rendering

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client v…

aliasvault | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-25590 — GLPI Inventory Plugin has Reflected XSS in task jobs

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vul…

glpi_inventory | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.2 HIGH
CVE-2026-3487 — itsourcecode College Management System class-result.php sql injection

A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.php. Performing a manipulation of the argument cour…

college_management_system | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
Showing 20 of 5095 Results