Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-6391 — Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to S…

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.5 MEDIUM
CVE-2026-6072 — Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key …

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin prote…

oliver_pos | Remote | Authorization
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.4 MEDIUM
CVE-2026-5293 — 診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scripting via '…

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing autho…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
3.7 LOW
CVE-2026-45232 — Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memor…

rsync | Remote | Memory Corruption
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
6.9 MEDIUM
CVE-2026-43620 — Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Atta…

rsync | Remote | Memory Corruption
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
7.2 HIGH
CVE-2026-43619 — Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat …

rsync | Race Condition
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
8.1 HIGH
CVE-2026-43618 — Rsync < 3.4.3 Integer Overflow Information Disclosure

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigg…

rsync | Remote | Memory Corruption
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
6.3 MEDIUM
CVE-2026-43617 — Rsync < 3.4.3 Authorization Bypass via Hostname Resolution

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass host…

rsync | Remote | Authorization
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
7.5 HIGH
CVE-2026-3985 — Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated…

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. T…

creative_mail | Remote | Injection
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
Showing 20 of 7589 Results