Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-11989 — Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Up…

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8…

Remote | Server-Side Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.4 MEDIUM
CVE-2026-4328 — Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) S…

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supp…

advanced_import | Remote | Server-Side Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.3 MEDIUM
CVE-2026-9013 — Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informatio…

The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This makes it possible for authent…

Remote | Information Disclosure
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.4 MEDIUM
CVE-2026-12157 — BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'block…

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category…

Remote | Cross-Site Scripting
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.9 MEDIUM
CVE-2026-7547 — Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parame…

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitizati…

Remote | Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.4 MEDIUM
CVE-2026-1856 — Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripti…

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient inpu…

Remote | Cross-Site Scripting
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.9 MEDIUM
CVE-2026-11752 — Armeria-xds: Arbitrary File Read via Unrestricted Filename Resolution

A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables with…

Remote | Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.3 MEDIUM
CVE-2026-10779 — Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Featur…

The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capabili…

Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.9 MEDIUM
CVE-2026-56132 — Expat Heap-Based Buffer Overflow

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.9 MEDIUM
CVE-2026-56131 — Expat XML_ResumeParser Use-After-Free Vulnerability

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50…

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.7 HIGH
CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) co…

Remote | Denial of Service
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.3 MEDIUM
CVE-2026-11775 — User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the use…

Remote | Cross-Site Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.7 HIGH
CVE-2026-8805 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP module

Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker…

Remote | Denial of Service
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.8 CRITICAL
CVE-2026-40624 — AVer PTC cameras Files or Directories Accessible to External Parties

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.1 HIGH
CVE-2026-50034 — Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensi…

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

| Information Disclosure
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.1 HIGH
CVE-2026-52866 — Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

| Denial of Service
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
5.3 MEDIUM
CVE-2026-12049 — pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' param…

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed bac…

pgadmin_4 | Remote | Misconfiguration
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.3 CRITICAL
CVE-2026-12048 — pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-…

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relat…

pgadmin_4 | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.8 MEDIUM
CVE-2026-12047 — pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised …

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propaga…

pgadmin_4 | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.5 CRITICAL
CVE-2026-12046 — pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection…

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only r…

pgadmin_4 | Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
Showing 20 of 7534 Results