Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2015-20116 — RealtyScript 4.0.2 Stored Cross-Site Scripting via CSV File Upload Filename

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can up…

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.2 HIGH
CVE-2015-20115 — RealtyScript 4.0.2 Stored Cross-Site Scripting via File Upload Parameter

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload …

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.1 MEDIUM
CVE-2015-20114 — RealtyScript 4.0.2 Cross-Site Scripting via Multiple Parameters

Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple para…

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.9 MEDIUM
CVE-2015-20113 — RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scriptin…

Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malici…

Remote | Cross-Site Request Forgery
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.7 HIGH
CVE-2013-20006 — Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users…

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.9 MEDIUM
CVE-2013-20005 — Qool CMS 2.0 RC2 Cross-Site Request Forgery via adduser

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers c…

Remote | Cross-Site Request Forgery
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.5 HIGH
CVE-2026-4111 — Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data()…

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processe…

Remote | Denial of Service
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.8 HIGH
CVE-2026-4105 — Systemd: systemd: privilege escalation via improper access control in registermachine d-b…

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop…

| Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.7 HIGH
CVE-2026-4092 — Arbitrary File Write via Path Traversal in Google clasp leading to RCE

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with dir…

Remote | Path Traversal
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-4063 — Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber…

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in …

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.8 HIGH
CVE-2026-3999 — Broken access control vulnerability affecting ID Server

A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations.

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
6.4 MEDIUM
CVE-2026-3986 — Calculated Fields Form <= 5.4.5.0 - Authenticated (Contributor+) Stored Cross-Site Script…

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capabilit…

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.8 HIGH
CVE-2026-3910 — Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffe…

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…

linux_kernel chrome macos windows | CISA KEV Remote | Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-3909 — Google Skia Out-of-Bounds Write Vulnerability - [Actively Exploited]

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows | CISA KEV Remote | Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
9.8 CRITICAL
CVE-2026-3891 — Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings'…

Remote | Authentication
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.2 HIGH
CVE-2026-3873 — Legacy built-in user account

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra: before 25.3.0.

Remote | Authentication
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.5 HIGH
CVE-2026-3045 — Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensi…

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due t…

Remote | Information Disclosure
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
9.8 CRITICAL
CVE-2026-32746 — GNU inetutils telnetd LINEMODE SLC Buffer Overflow

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Remote | Memory Corruption
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
6.3 MEDIUM
CVE-2026-32745 — JetBrains Datalore Session Hijacking Vulnerability

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

| Authentication
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.4 MEDIUM
CVE-2026-32612 — Statamic: privilege escalation via stored cross-site scripting

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to in…

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
Showing 20 of 5305 Results