Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12570 — Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.…

| Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19089 — Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as a…

| Misconfiguration
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19077 — Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Le…

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Dup…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19075 — All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Para…

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`…

| Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19074 — Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom …

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX act…

| Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-18786 — CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose …

| Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-18200 — FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access …

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-15047 — s2Member < 260805 - Contributor+ Stored XSS via Shortcode

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to injec…

| Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-14293 — Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output o…

| Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-14238 — Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report

The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing u…

| Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-14237 — Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-14211 — Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allo…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-17023 — Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connect…

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked …

| Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-17022 — Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Dis…

The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated…

| Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-17021 — Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total…

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, a…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-17020 — Salon Booking System – Free Version <= 10.30.33 - Subscriber+ Arbitrary Booking PII Discl…

The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, al…

| Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-15229 — Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulati…

The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (includ…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19053 — ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter

The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injec…

| Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19049 — ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'remove…

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capab…

| Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-18960 — Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the bloc…

| Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 9517 Results