Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-43074 — eventpoll: defer struct eventpoll free to RCU grace period

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep…

linux_kernel | Memory Corruption
May 06, 2026 May 08, 2026
May 06, 2026
May 08, 2026
6.1 MEDIUM
CVE-2026-42509 — Apache Wicket: crafted strings can break out of the JavaScript sequence

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 t…

wicket | Remote | Cross-Site Scripting
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-40010 — Apache Wicket: possible session fixation using AuthenticatedWebSession

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.…

wicket | Remote | Authentication
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.2 MEDIUM
CVE-2026-40001 — Local privilege escalation vulnerability in ZTE PROCESS Guard service of the cloud comput…

There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traver…

| Path Traversal
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.6 MEDIUM
CVE-2026-35255 — Oracle Cloud Native Environment Command Line Interface Environment Variable Injection Vul…

Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability…

May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2026-1719 — Gravity Bookings <= 2.5.9 - Unauthenticated SQL Injection via 'category_id' Parameter

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of su…

Remote | Injection
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
8.8 HIGH
CVE-2026-7841 — GV-ASWeb Remote Code Execution (RCE) vulnerability

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server b…

Remote | Injection
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.4 MEDIUM
CVE-2026-7457 — LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer…

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profi…

Remote | Cross-Site Scripting
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.2 HIGH
CVE-2026-7332 — LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_u…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, …

Remote | Cross-Site Scripting
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.4 MEDIUM
CVE-2026-6672 — Affiliate Program Suite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to…

affiliate_program_suite | Remote | Cross-Site Scripting
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.9 MEDIUM
CVE-2026-6344 — Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Trave…

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNo…

contact_form | Remote | Path Traversal
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.1 MEDIUM
CVE-2026-35254 — Oracle OCI CLI Path Traversal Vulnerability

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with netw…

cloud_infrastructure_cli | Path Traversal
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.7 MEDIUM
CVE-2026-35253 — Oracle Macaron Tool HTTP Host Address Validation Bypass

Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated attacker w…

macoron | Remote | Misconfiguration
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.3 HIGH
CVE-2026-23928 — Stored XSS vulnerability in the Item history/Plain text widget

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized acti…

zabbix | Remote | Cross-Site Scripting
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.1 MEDIUM
CVE-2026-23927 — Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle datab…

zabbix | Remote | Injection
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
7.3 HIGH
CVE-2026-23926 — Stored XSS vulnerability in Host navigator widget maintenance tooltip

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator …

zabbix | Remote | Cross-Site Scripting
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
4.3 MEDIUM
CVE-2026-2306 — Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ta…

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in al…

ninja_tables | Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.5 MEDIUM
CVE-2026-5753 — All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authentica…

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::s…

Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
5.3 MEDIUM
CVE-2026-3208 — Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticate…

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all ver…

mercado_pago_payments_for_woocommerce | Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
5.0 MEDIUM
CVE-2026-7573 — GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across …

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy …

Remote | Authorization
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
Showing 20 of 5779 Results