Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-15019 — Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_i…

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible f…

| Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-76562 — Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_desc…

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sa…

| Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-14873 — Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating …

| Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-4657 — Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via cont…

The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin reg…

| Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-15820 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Script…

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient in…

| Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-18594 — Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated (Custom+) Un…

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is …

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-18386 — WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to…

The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possib…

| Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-15823 — Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) …

The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0…

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-15796 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Script…

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input…

| Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.4 MEDIUM
CVE-2026-87870 — Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site …

The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 d…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.5 HIGH
CVE-2026-84063 — BurgerEditor Unrestricted File Upload Vulnerability

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can l…

| Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-84062 — BurgerEditor Authorization Bypass

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who…

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.7 HIGH
CVE-2026-19584 — Velociraptor VQL injection during notebook restore from backup

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template …

velociraptor | Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-19583 — Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires t…

velociraptor | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.8 CRITICAL
CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File U…

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This …

Remote | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-87933 — DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attac…

cjson | Remote | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.6 CRITICAL
CVE-2026-87931 — Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Ce…

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Servic…

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.0 MEDIUM
CVE-2026-87926 — Rizwan17 inventory-management-system Login Page index.php cross site scripting

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login P…

inventory-management-system | Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-87925 — Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file incl…

inventory-management-system | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.5 HIGH
CVE-2026-59185 — Identrail GitHub App Installation ID Authorization Bypass

## Summary identrail's GitHub App connection-completion endpoint binds a fully client-supplied `installation_id` to the caller's workspace without verifying that the installation belongs to, or was …

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13950 Results