Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-15403 — Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via '…

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escapin…

| Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-15006 — Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Fie…

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via t…

| Path Traversal
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-13362 — SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) Stored Cross…

The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient …

| Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-15414 — Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalatio…

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_…

| Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-7623 — SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headin…

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and …

| Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.5 HIGH
CVE-2026-9044 — Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device b…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-54909 — Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-…

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing pat…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.1 LOW
CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-…

sigstore-go | Remote | Cryptography
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
6.2 MEDIUM
CVE-2026-54785 — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inlin…

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied i…

| Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2026-54768 — WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user ex…

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-cl…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-53573 — core-geonetwork has an Open Redirect Bypass

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and Keycloak…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-45377 — Decidim: Private exports can be downloaded through reusable links

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged…

decidim | Remote | Authorization
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
5.5 MEDIUM
CVE-2026-45376 — Decidim: Admin user search allows SQL injection through similarity-based sorting

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] in…

decidim | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.9 MEDIUM
CVE-2026-45330 — Decidim: Verification admins can access supplied IDs from other organisations

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Auth…

decidim | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.8 HIGH
CVE-2026-34641 — Premiere Pro | Out-of-bounds Write (CWE-787)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

premiere | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-68771 — ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted p…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52371 — XXL-Job Server-Side Request Forgery

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

| Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52232 — FS Inc S3150-8T2F Switch Reflected Cross-Site Scripting

A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the …

| Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52134 — libiec61850 Authentication Bypass Vulnerability

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-51953 — FeehiCMS Privilege Escalation Vulnerability

An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9405 Results