Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-1785 — Code Snippets <= 3.9.4 - Cross-Site Request Forgery to Cloud Snippet Download/Update Acti…

The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download a…

Remote | Cross-Site Request Forgery
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
9.8 CRITICAL
CVE-2026-1499 — WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_ad…

The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on t…

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1252 — Events Listing Widget <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitiz…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.2 MEDIUM
CVE-2026-2010 — Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/lo…

publiccms | Remote | Authorization
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.5 MEDIUM
CVE-2026-2009 — SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead …

gas_agency_management_system | Remote | Authorization
Feb 06, 2026 Feb 10, 2026
Feb 06, 2026
Feb 10, 2026
9.2 CRITICAL
CVE-2026-21626 — Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss …

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

easydiscuss | Remote | Information Disclosure
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1279 — Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and includi…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
8.8 HIGH
CVE-2026-2008 — abhiphile fermat-mcp eqn_chart.py eqn_chart code injection

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the file fmcp/mpl_mcp/core/eqn_chart.py. Perf…

fermat | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
7.2 HIGH
CVE-2026-2000 — DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection

A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a…

dcme-320_firmware dcme-320 | Remote | Injection
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
5.5 MEDIUM
CVE-2026-1998 — micropython runtime.c mp_import_all memory corruption

A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be l…

micropython | Memory Corruption
Feb 06, 2026 Feb 17, 2026
Feb 06, 2026
Feb 17, 2026
6.4 MEDIUM
CVE-2026-1909 — WaveSurfer-WP <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sr…

The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1888 — Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplaylist' shortcode in all versions up to, and including, 1.0.6 due to insufficient …

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1808 — Orange Confort+ accessibility toolbar for WordPress <= 0.7 - Authenticated (Contributor+)…

The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up t…

Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.4 MEDIUM
CVE-2026-1401 — Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross…

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and outpu…

tune_library | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
6.1 MEDIUM
CVE-2026-0521 — Reflected Cross-Site Scripting in PDF Export Error Message

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a vict…

map\+ | Remote | Cross-Site Scripting
Feb 06, 2026 Feb 18, 2026
Feb 06, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-10753 — OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and aut…

oauth_single_sign_on | Remote | Authentication
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1991 — libuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference

A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null poin…

libuvc | Memory Corruption
Feb 06, 2026 Mar 05, 2026
Feb 06, 2026
Mar 05, 2026
4.2 MEDIUM
CVE-2026-0598 — Ansible-lightspeed: broken object level authorization leading to cross-user ai conversati…

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the …

Remote | Authorization
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
4.8 MEDIUM
CVE-2026-1990 — oatpp Type.hpp ObjectWrapper null pointer dereference

A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation l…

| Memory Corruption
Feb 06, 2026 Feb 06, 2026
Feb 06, 2026
Feb 06, 2026
5.5 MEDIUM
CVE-2026-1979 — mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after fr…

mruby | Memory Corruption
Feb 06, 2026 Feb 28, 2026
Feb 06, 2026
Feb 28, 2026
Showing 20 of 5121 Results