Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19035 — Shibby Tomato qoslimit new_qoslimit_start os command injection

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable le…

tomato | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.4 MEDIUM
CVE-2026-8166 — Stored XSS in Logo Software's e-Logo Purchasing Portal

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue aff…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2025-9266 — Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Dem…

The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. …

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2025-15028 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & Mo…

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all ver…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-11983 — Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` f…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-5391 — LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-5158 — PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comme…

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to,…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-57818 — Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid acces…

cxf | Race Condition
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-61466 — Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it …

cxf | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-63687 — Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly…

cxf | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-65583 — Apache CXF: Self-issued ID token claims validation skipped

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication…

cxf | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-68079 — Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality.…

cxf | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-68481 — Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This viola…

cxf | Cryptography
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-66909 — Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the se…

cxf | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-65432 — Apache CXF: XXE via WSDL/XSD import parsing

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is…

cxf | XML External Entity
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-64958 — Apache CXF: Denial of service via message header attachments

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to up…

cxf | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-57819 — Apache CXF: No default restriction on the amount of form parameters per message

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial o…

cxf | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-57817 — Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or miscon…

cxf | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-54225 — Apache CXF: Denial of Service attack via large attachments

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial…

cxf | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.3 HIGH
CVE-2026-19034 — Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argume…

tomato | Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9867 Results