Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-17037 — Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all versions up to, and including, 6.2…

| Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-87727 — a-blog cms Path Traversal Vulnerability

a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.

a-blog_cms | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.3 HIGH
CVE-2026-80469 — CVE-2026-80469

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-19486 — SSRF in Gemini Enterprise Agent Platform App Builder

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacke…

Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.3 HIGH
CVE-2025-15679 — BMC root account active without password

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password.

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-87859 — morgan vulnerable to Log Injection via unescaped double quote in quoted log fields

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the A…

| Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.2 CRITICAL
CVE-2026-47839 — Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. …

cf-deployment | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-89179 — Howyar|WeenyGenius - Missing Support for Integrity Check

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's …

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-89178 — Howyar|WeenyGenius - Origin Validation Error

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and…

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-89177 — Howyar|WeenyGenius - Use of Insecure Protocol

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same networ…

| Cryptography
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-89176 — Howyar|WeenyGenius - Missing Authentication

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or t…

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89175 — Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-89174 — Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protec…

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts throug…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89173 — Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting…

Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6642 — Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to ins…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6641 — Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input s…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6640 — Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient in…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-87908 — multiparty vulnerable to Denial of Service via unbounded part-header accumulation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumul…

| Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
0.0 NA
CVE-2026-86815 — BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing …

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a …

| Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
0.0 NA
CVE-2026-86812 — WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-order…

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allow…

| Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13418 Results