Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-6248 — wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Pr…

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not valid…

| Path Traversal
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
4.5 MEDIUM
CVE-2026-6060 — Possible DoS via SQL Box

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS…

Remote | Denial of Service
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
6.3 MEDIUM
CVE-2026-41389 — OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Pat…

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result …

Remote | Path Traversal
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.4 MEDIUM
CVE-2026-39112 — Apartment Visitors Management System Cross Site Scripting

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can injec…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
7.5 HIGH
CVE-2026-39111 — Apartment Visitors Management System SQL Injection

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an …

Remote | Injection
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-39110 — Apache Openvisit SQL Injection Vulnerability

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows…

| Injection
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-39109 — Apartment Visitors Management System SQL Injection

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticat…

| Injection
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-26399 — Arduin_Core_STM32 Stack Use-After-Return Buffer Overflow Vulnerability

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to…

| Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
6.4 MEDIUM
CVE-2026-23758 — GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the …

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.4 MEDIUM
CVE-2026-23757 — GFI HelpDesk < 4.99.10 Stored XSS via Reports Module

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.4 MEDIUM
CVE-2026-23756 — GFI HelpDesk < 4.99.9 Stored XSS via Troubleshooter Step Subject

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and Ed…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
4.8 MEDIUM
CVE-2026-23753 — GFI HelpDesk < 4.99.9 Stored XSS via charset Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create(…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
4.8 MEDIUM
CVE-2026-23752 — GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary J…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
7.5 HIGH
CVE-2026-6662 — ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results i…

Remote | Misconfiguration
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
8.8 HIGH
CVE-2026-41445 — KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_ff…

Remote | Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
8.7 HIGH
CVE-2026-40488 — OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Cod…

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…

Remote | Misconfiguration
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.3 MEDIUM
CVE-2026-40098 — OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to privat…

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…

Remote | Authorization
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
6.3 MEDIUM
CVE-2026-35154 — "Dell PowerProtect Data Domain IDRAC Privilege Escalation Vulnerability"

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper …

| Authorization
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-30269 — Doorman Privilege Escalation Vulnerability

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is a…

| Authorization
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
7.8 HIGH
CVE-2026-30266 — DeepCool DeepCreative Privilege Escalation Vulnerability

Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.7 and before allows a local attacker to execute arbitrary code via a crafted file

| Misconfiguration
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
Showing 20 of 5991 Results