Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-28773 — Authenticated OS Command Injection via Ping Utility Leading to RCE as Root

The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Management Interface version 101 is vulnerable t…

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.1 MEDIUM
CVE-2026-28772 — Reflected XSS in IDC_Logging Index endpoint

A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interf…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.1 MEDIUM
CVE-2026-28771 — Reflected XSS In /index.cgi Endpoint On IDC Satellite Receiver Web Management Interface V…

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface …

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.4 MEDIUM
CVE-2026-2732 — Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitra…

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all vers…

enable_media_replace | Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-2363 — WP-Members Membership Plugin <= 3.5.5.1 - Authenticated (Contributor+) SQL Injection via …

The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, …

wp-members | Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-28770 — XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interfac…

Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface …

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-28769 — LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumera…

A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 1…

Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-2025 — Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the b…

Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.8 MEDIUM
CVE-2026-3242 — Concrete CMS below 9.4.8 is vulnerable to Stored XSS in the Switch Language block

In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vec…

concrete_cms concrete5 | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.8 MEDIUM
CVE-2026-3241 — Concrete CMS below version 9.4.8 is vulnerable to a stored cross-site scripting (XSS) in …

In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue…

concrete_cms concrete5 | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.8 MEDIUM
CVE-2026-3240 — Concrete CMS below 9.4.8 is vulnerable to Stored XSS via Legacy form

In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concret…

concrete_cms concrete5 | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.8 MEDIUM
CVE-2026-2994 — Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allow…

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since change…

concrete_cms concrete5 | Remote | Cross-Site Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.9 HIGH
CVE-2026-3452 — Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Ex…

Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can …

concrete_cms concrete5 | Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.8 MEDIUM
CVE-2026-3244 — Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page N…

In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search resu…

concrete_cms concrete5 | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-2292 — Morkva UA Shipping <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting …

The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and outp…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-2289 — Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Bl…

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output esca…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-1980 — WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Expo…

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This…

wpbookit | Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1945 — WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and '…

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient …

wpbookit | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-1651 — Email Subscribers & Newsletters <= 5.9.16 - Authenticated (Administrator+) SQL Injection …

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping…

Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1273 — PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API …

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/…

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
Showing 20 of 5071 Results