Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.6 MEDIUM
CVE-2026-77988 — TRENDnet TEW-823DRU CLI Configuration Tool nvram_get command injection

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection.…

tew-823dru tew-823dru | Remote | Injection
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
8.6 HIGH
CVE-2026-66917 — Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

Remote | Cross-Site Scripting
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
6.9 MEDIUM
CVE-2026-66916 — Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON F…

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON v…

Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
4.3 MEDIUM
CVE-2026-4245 — Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributor+) Post Dup…

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only…

post_duplicator | Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
5.3 MEDIUM
CVE-2026-3424 — kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload'…

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the sof…

Remote | Injection
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
10.0 CRITICAL
CVE-2026-77946 — TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based ov…

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configur…

tew-821dap | Remote | Memory Corruption
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
7.4 HIGH
CVE-2026-77945 — TRENDnet TEW-821DAP ssi upload.cgi command injection

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename re…

tew-821dap | Remote | Injection
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
9.8 CRITICAL
CVE-2026-78003 — Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via '…

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validati…

Remote | Server-Side Request Forgery
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
9.3 CRITICAL
CVE-2026-12710 — Missing Authorization in Application Integration QueryEngineTask

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal …

application_integration | Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77002 — SmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication Bypass

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any re…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77001 — Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Auth…

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77000 — WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticate…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-76793 — Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email Cla…

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session,…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-76789 — Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and Add-Slider Ha…

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19222 — Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Ro…

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configur…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19221 — Forminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multis…

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execu…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19093 — Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, inclu…

| Path Traversal
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-18052 — ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login …

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, a…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-16738 — Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Fo…

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or v…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-16612 — FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumer…

| Information Disclosure
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
Showing 20 of 11522 Results