Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7726 — Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache M…

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nop…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.2 HIGH
CVE-2026-7693 — Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'fi…

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `res…

Remote | Injection
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.1 HIGH
CVE-2026-7520 — MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscribe…

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all vers…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.1 HIGH
CVE-2026-7444 — Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the …

Remote | Cross-Site Request Forgery
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
6.4 MEDIUM
CVE-2026-7441 — Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2…

Remote | Cross-Site Scripting
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
4.3 MEDIUM
CVE-2026-7105 — Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Pos…

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including,…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.5 HIGH
CVE-2026-71215 — art-template: Path Traversal in Sub-Template Resolution via include()/extend()

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(roo…

Remote | Path Traversal
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
9.8 CRITICAL
CVE-2026-71214 — NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization …

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
9.1 CRITICAL
CVE-2026-71213 — typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configurat…

Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
4.4 MEDIUM
CVE-2026-71212 — xidown: Argument Injection via Unterminated yt-dlp Command Line Construction

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional a…

| Injection
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.1 HIGH
CVE-2026-71211 — mlflow: Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value…

Remote | Server-Side Request Forgery
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.3 MEDIUM
CVE-2026-71210 — mealie: DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud Metadata Acc…

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTT…

Remote | Server-Side Request Forgery
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.5 HIGH
CVE-2026-71209 — audiobookshelf: %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabl…

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/i…

Remote | Path Traversal
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
6.5 MEDIUM
CVE-2026-71208 — KubeSphere: SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discover…

Remote | Server-Side Request Forgery
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
9.8 CRITICAL
CVE-2026-71207 — Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credential…

The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session valu…

Remote | Injection
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.3 HIGH
CVE-2026-71206 — shiori: JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access …

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the datab…

shiori | Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
6.5 MEDIUM
CVE-2026-71205 — changedetection.io: No Rate Limiting on /login Enables Unlimited Password Brute-Force

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limit…

Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
6.2 MEDIUM
CVE-2026-71204 — changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcem…

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an u…

Remote | Misconfiguration
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.3 MEDIUM
CVE-2026-71203 — changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Sc…

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetec…

Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.5 HIGH
CVE-2026-71202 — raster: Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic

The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source wid…

Remote | Memory Corruption
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
Showing 20 of 9697 Results