Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-55373 — OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample cou…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop v…

| Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-55371 — OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL po…

| Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-55059 — OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulner…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bound…

| Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil i…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the …

| Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.1 HIGH
CVE-2026-53532 — OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file c…

Remote | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.7 MEDIUM
CVE-2026-78435 — Faveo Helpdesk Logo SettingsController.php unlink path traversal

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Suc…

Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78434 — Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing au…

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component p…

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-78284 — WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-78282 — WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-78268 — WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram,…

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

Remote | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-78267 — WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

translatepress | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78266 — WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-78265 — WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-78264 — WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-78263 — WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-78262 — WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

wp_project_manager | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.3 HIGH
CVE-2026-78259 — WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-77384 — libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remo…

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally…

Remote | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-77337 — CakePHP: Potential Authentication bypass with CookieAuthenticator

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow …

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-68516 — OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can c…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11484 Results