Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-63569 — MTI/A0 DHAgreement does not validate the peer's ephemeral value

Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local pa…

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-63568 — Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion

Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthentica…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-63567 — IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)

Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit mo…

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-63566 — DTLS handshake reassembler allocates buffer from unchecked 24-bit length

Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauth…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-97219 — MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status o…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.4 MEDIUM
CVE-2026-92924 — Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via…

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as su…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-91020 — WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulat…

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon va…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-90987 — Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipula…

The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an …

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-90952 — WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass v…

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of publish…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.4 MEDIUM
CVE-2026-85005 — Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Mi…

The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-priv…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-84740 — The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via '…

The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthentica…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-79618 — WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level acc…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-1661 — WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection

The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to injec…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-13413 — CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Lo…

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to b…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-16001 — IesEngine stream-mode MAC forgery via length-dependent KDF split

Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-cs…

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-16000 — KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used

Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages …

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-15999 — AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to …

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-102565 — BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_s…

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.0 CRITICAL
CVE-2026-93029 — WHM Stored Cross-Site Scripting

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.0 CRITICAL
CVE-2026-93697 — WHM Stored Cross-Site Scripting Vulnerability

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14862 Results