Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-23549 — WordPress WpEvently plugin <= 5.1.1 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.

Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-23548 — WordPress DirectoryPress plugin <= 3.6.25 - Broken Access Control vulnerability

Missing Authorization vulnerability in designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a …

directorypress | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-23547 — WordPress CMSMasters Content Composer plugin <= 2.5.8 - Broken Access Control vulnerabili…

Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM…

Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-23545 — WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Ca…

aruba_hispeed_cache | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-23544 — WordPress Valenti theme <= 5.6.3.5 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

Remote | Injection
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-23543 — WordPress Essential Addons for Elementor plugin <= 6.5.5 - Broken Access Control vulnerab…

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

essential_addons_for_elementor | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-23542 — WordPress Grand Restaurant theme <= 7.0.10 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.

grand_restaurant | Remote | Injection
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
0.0 NA
CVE-2026-23541 — WordPress Mail Mint plugin <= 1.19.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4.

| Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-22422 — WordPress Everest Forms plugin <= 3.4.1 - Arbitrary Shortcode Execution vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a t…

everest_forms | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.2 HIGH
CVE-2026-22333 — WordPress YITH WooCommerce Compare plugin <= 3.6.0 - Deserialization of untrusted data vu…

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= …

Remote | Injection
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
4.7 MEDIUM
CVE-2026-22269 — Dell PowerProtect Data Manager Improper Verification of Source of a Communication Channel

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remo…

powerprotect_data_manager | Remote | Authentication
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.9 MEDIUM
CVE-2025-41023 — Authentication bypass in AutoGPT de Thesamur

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker c…

Remote | Authentication
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.1 MEDIUM
CVE-2025-40697 — Reflected Cross-Site Scripting (XSS) in Lewe WebMeasure

Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be …

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
3.8 LOW
CVE-2026-2733 — Org.keycloak/keycloak-services: keycloak: missing check on disabled client for docker reg…

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that …

Remote | Authentication
Feb 19, 2026 Mar 05, 2026
Feb 19, 2026
Mar 05, 2026
6.3 MEDIUM
CVE-2026-2711 — zhutoutoutousan worldquant-miner URL ssrf_proxy.py server-side request forgery

A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-miner-master/agent-dify-api/core/helper/ssrf_proxy.p…

Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
10.0 CRITICAL
CVE-2026-2731 — Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

Remote | Path Traversal
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.1 MEDIUM
CVE-2026-2709 — busy Callback app.js redirect

A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulatio…

Remote | Misconfiguration
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
7.5 HIGH
CVE-2026-2706 — code-projects Patient Record Management System fecalysis_not.php sql injection

A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This manipulation of the argument comp_id causes sql inje…

Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.1 HIGH
CVE-2026-2705 — Open Babel MOL2 File atom.h SetFormalCharge out-of-bounds

A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of the component MOL2 File Handler. The ma…

open_babel | Remote | Memory Corruption
Feb 19, 2026 Mar 01, 2026
Feb 19, 2026
Mar 01, 2026
8.1 HIGH
CVE-2026-2704 — Open Babel CIF File transform3d.cpp DescribeAsString out-of-bounds

A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file src/math/transform3d.cpp of the compone…

open_babel | Remote | Memory Corruption
Feb 19, 2026 Mar 01, 2026
Feb 19, 2026
Mar 01, 2026
Showing 20 of 5329 Results