Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escala…

support_assistant | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85187 — itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate s…

A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=e…

online_medicine_delivery_system | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-85012 — OS command injection in the Amazon CodeCatalyst blueprints SDK

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-84968 — Heap out-of-bounds read via corrupt nested BSON in field path error message

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory…

php_driver | Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.8 HIGH
CVE-2026-83959 — Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…

substance_3d_sampler | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.4 MEDIUM
CVE-2026-82024 — LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by s…

learnpress | Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-82023 — LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Ins…

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned…

learnpress | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-63219 — Unauthenticated file upload via missing authorization on formatter upload endpoint

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and all…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.1 CRITICAL
CVE-2026-58400 — GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configurat…

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure proc…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-49456 — Waku: Open Redirect via `unstable_redirect` Helper

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arb…

| Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-49455 — Waku: Cross-Origin CSRF on RSC Server Action Dispatch

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-or…

| Cross-Site Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-82526 — R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.8 HIGH
CVE-2026-85028 — Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development…

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to…

| Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85309 — WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: fr…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85308 — WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerabi…

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: fr…

sureforms | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85307 — WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.

Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85306 — WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Access Control…

Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mount…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.4 MEDIUM
CVE-2026-85305 — WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.

Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85304 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. …

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85303 — WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Ren…

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12623 Results