Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-87739 — PaperCut MF/NG: User permissions are not evaluated on report generation

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials,…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.3 HIGH
CVE-2026-82077 — PaperCut NG/MF: Remote Code Execution via Scan2Fax

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to exec…

Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.9 MEDIUM
CVE-2026-81645 — Graphics Module Out-of-Bounds Read Vulnerability

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
3.8 LOW
CVE-2026-11744 — PaperCut Hive Embedded App for Ricoh: Javascript injection

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process bef…

| Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-97181 — ezGlobal|GPM LIGHT - Sensitive Data Exposure

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.6 MEDIUM
CVE-2026-97177 — Keycloak-services: keycloak-services: generic user update bypasses denied reset-password …

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations dur…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.2 MEDIUM
CVE-2026-97176 — Keycloak-services: keycloak-services: essential acr requirement silently bypassed via coo…

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security l…

single_sign-on build_of_keycloak | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-93662 — Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via …

The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read …

events_manager | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-93661 — Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event…

events_manager | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-89005 — WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Cont…

wpematico_rss_feed_fetcher | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-89004 — WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclos…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributo…

wpematico_rss_feed_fetcher | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-89002 — WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contri…

wpematico_rss_feed_fetcher | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88847 — MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated use…

masterstudy_lms | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88846 — MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Dis…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registrati…

masterstudy_lms | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88845 — MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as …

masterstudy_lms | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88843 — MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Wid…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor …

masterstudy_lms | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-84151 — The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-…

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and ab…

the_post_grid | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-82850 — Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the …

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-82849 — Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-regi…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-82195 — 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthentic…

10web_booster | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14352 Results