Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-18234 — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-18233 — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscriber…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-17522 — Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowin…

| Cross-Site Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-17520 — Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute t…

| Cryptography
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-16947 — Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to P…

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify…

| Server-Side Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-16600 — SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_u…

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users…

| Server-Side Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-16259 — Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that …

| Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-16061 — Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated att…

| Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-10522 — Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.7 HIGH
CVE-2026-41012 — BOSH vSphere CPI Improper Cert Validation

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via…

| Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.3 MEDIUM
CVE-2026-55867 — Graylog token revocation endpoint allows authenticated users to delete other users’ acces…

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in gra…

graylog | Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (cle…

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55859 — MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding …

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the …

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55858 — MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariad…

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and per…

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently P…

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitt…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55856 — MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-fu…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-55855 — MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5…

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-55854 — MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficie…

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an accou…

Remote | Cryptography
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-55848 — mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in…

print | Remote | XML External Entity
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-55841 — Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from…

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-serv…

graylog | Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12165 Results