Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-69075 — Stored Cross-Site Scripting via Vue Template Injection in FlowIntel

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, …

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-8794 — PaperCut NG/MF: User enumeration via timing attack

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measurin…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-8793 — PaperCut NG/MF: Insufficient brute-force protection

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-28147 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. …

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21555 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

udx710 | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21554 — Modem Improper Input Validation Vulnerability

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

udx710 | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21553 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21552 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21551 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21550 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21549 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21548 — NR Modem Improper Input Validation Vulnerability

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.6 MEDIUM
CVE-2026-18593 — vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox

A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handle…

pentagi | Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.8 MEDIUM
CVE-2026-18592 — osCommerce Email Template Configuration EmailController.php EmailController sql injection

A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
2.1 LOW
CVE-2026-18591 — Meesho Online Shopping App com.meesho.supply cleartext storage

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulatio…

| Information Disclosure
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-18590 — Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection

A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os comm…

wl-nu516u1 | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.3 MEDIUM
CVE-2026-12259 — Improper Input Validation in nltk/nltk

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. …

Remote | Supply Chain
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-62416 — Sharp Corporation Network Scanner Tool Unauthenticated Arbitrary File Upload and Denial o…

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products ar…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-63563 — Sharp and Toshiba Tec MFPs Unauthorized Access Vulnerability

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial confi…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
2.4 LOW
CVE-2026-63545 — Sharp and Toshiba Tec MFPs Sensitive Data Exposure via Insecure Cache Persistence

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

| Information Disclosure
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9258 Results