Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-1294 — All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via …

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the …

Remote | Server-Side Request Forgery
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.3 MEDIUM
CVE-2026-1271 — ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) …

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' …

profilegrid | Remote | Authorization
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.3 MEDIUM
CVE-2025-14079 — ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to A…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability chec…

wsdesk | Remote | Authorization
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.4 MEDIUM
CVE-2026-1319 — Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via …

The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image i…

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
4.3 MEDIUM
CVE-2025-13416 — ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() fun…

profilegrid | Remote | Authorization
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
5.1 MEDIUM
CVE-2026-25198 — Web2py Open Redirect Vulnerability

web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website wh…

web2py | Misconfiguration
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.3 MEDIUM
CVE-2025-10258 — A time-based SQL Injection vulnerability in Infinera DNA

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.

infinera_dna | Injection
Feb 05, 2026 Feb 26, 2026
Feb 05, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-1953 — Stored Cross Site Scripting(XSS) in Nukegraphic CMS V3.1.2

Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize …

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.4 MEDIUM
CVE-2026-1268 — Dynamic Widget Content <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content field in the Gutenberg editor sidebar in all versions up to, and including, 1.3.6 d…

Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
4.9 MEDIUM
CVE-2026-1246 — ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'lo…

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient…

image_optimizer | Remote | Path Traversal
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
6.4 MEDIUM
CVE-2026-0867 — Essential Widgets <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via M…

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortcodes in all versions up to, and…

essential_widgets | Remote | Cross-Site Scripting
Feb 05, 2026 Feb 05, 2026
Feb 05, 2026
Feb 05, 2026
8.8 HIGH
CVE-2025-15080 — Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability …

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device da…

melsec_iq-r_firmware | Remote | Information Disclosure
Feb 05, 2026 Feb 06, 2026
Feb 05, 2026
Feb 06, 2026
Showing 20 of 5112 Results