Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-16723 — Remote Code Execution in fastjson 1.2.68–1.2.83

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required,…

fastjson | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-9729 — Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, …

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-9713 — Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Inject…

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX actio…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-9635 — WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Sc…

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is du…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-59678 — portprotonqt allows any users to mount and unmount arbitrary file systems and modify the …

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This …

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.8 MEDIUM
CVE-2026-59677 — Process Kill Attack Vector in killall() in seunshare

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context …

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-12421 — ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-52688 — RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

recursor | Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
3.7 LOW
CVE-2026-52686 — Wildcard CNAME proof validation bypass

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

recursor | Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2024-58330 — Bosch IP Cameras Missing Authentication Vulnerability

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2024-58023 — Bosch Configuration Manager Information Disclosure

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

configuration_manager | Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
3.7 LOW
CVE-2026-52684 — Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are u…

recursor | Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-16287 — Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Inj…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-9577 — Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-l…

| Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-9066 — WP Compress < 7.10.04 - Reflected XSS via test_zone

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the…

| Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.8 MEDIUM
CVE-2026-59676 — Local File Deletion Attack Vector in rm_rf() in seunshare

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete ar…

| Race Condition
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-14291 — Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who …

| Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-12082 — Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink M…

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post …

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-7534 — SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scriptin…

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-7232 — FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Pa…

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitizatio…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9664 Results