Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-31845 — Rukovoditel CRM Zadarma Telephony API Reflected XSS

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflect…

Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.2 MEDIUM
CVE-2026-32146 — Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modifica…

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and…

| Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
0.0 NA
CVE-2026-23900 — Extension - phoca.cz - Stored XSS vectors in Phoca Maps component 5.0.0 - 6.0.2 for Joomla

Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.

| Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.1 HIGH
CVE-2026-5809 — wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[bod…

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action han…

wpforo_forum | Remote | Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
9.6 CRITICAL
CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prot…

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could re…

acrobat_reader | Remote | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.1 MEDIUM
CVE-2026-5226 — Optimole <= 4.2.3 - Reflected Cross-Site Scripting via Page Profiler URL

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient outp…

orbit_fox | Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.2 HIGH
CVE-2026-5217 — Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Par…

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2…

orbit_fox | Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.5 MEDIUM
CVE-2026-5207 — LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter

The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 9.2.1. This is due to insufficient escaping on the user supplied para…

lifterlms | Remote | Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
8.8 HIGH
CVE-2026-5144 — BuddyPress Groupblog <= 1.9.3 - Authenticated (Subscriber+) Privilege Escalation to Admin…

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblo…

Remote | Authorization
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
5.0 MEDIUM
CVE-2026-4979 — UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop…

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, an…

userswp | Remote | Server-Side Request Forgery
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.4 MEDIUM
CVE-2026-4895 — Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disab…

The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.8.9 This is due to insufficient input sanitiz…

greenshift_-_animation_and_page_builder_blocks | Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.4 MEDIUM
CVE-2026-3498 — BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clie…

The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and including, 2.2.15. This is due to insufficient inpu…

Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
4.3 MEDIUM
CVE-2026-3371 — Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbi…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authori…

tutor_lms | Remote | Authorization
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
5.4 MEDIUM
CVE-2026-3358 — Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Pr…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing p…

tutor_lms | Remote | Authorization
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5496 — Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vu…

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5495 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5494 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5493 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
9.8 CRITICAL
CVE-2026-5059 — aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authent…

| Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
9.8 CRITICAL
CVE-2026-5058 — aws-mcp-server Command Injection Remote Code Execution Vulnerability

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication …

| Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
Showing 20 of 6222 Results