Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82919 — cu silicon edit Endpoint views.py create_app missing authentication

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to mis…

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82914 — kishan0725 Hospital-Management-System search.php sql injection

A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in …

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.3 MEDIUM
CVE-2026-82909 — QuantumNous new-api Revoked API Token token session expiration

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler.…

new-api | Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.8 HIGH
CVE-2026-82908 — MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. P…

dragon_center | Memory Corruption
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
3.7 LOW
CVE-2026-82906 — sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authent…

A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpo…

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-82852 — WordPress MapSVG plugin <= 8.15.0 - Server Side Request Forgery (SSRF) vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82392 — pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGr…

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it w…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.0 HIGH
CVE-2026-82346 — HP ImageDiags - Potential Escalation of Privilege

A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to in…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82229 — WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.1 HIGH
CVE-2026-82228 — WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.8 CRITICAL
CVE-2026-82226 — WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.4 HIGH
CVE-2026-82225 — WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

registrationmagic | Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82224 — WordPress SliceWP plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82221 — WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

registrationmagic | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.1 HIGH
CVE-2026-81892 — EasyAdmin custom-action dispatcher bypasses access_control on other routes

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom act…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.1 HIGH
CVE-2026-81891 — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() witho…

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-81890 — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConn…

Remote | Cross-Site Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.6 HIGH
CVE-2026-81889 — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protecti…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-81888 — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF…

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, …

Remote | Cross-Site Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.1 MEDIUM
CVE-2026-81887 — Livewire DOM-based cross-site scripting during client-side state handling

Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotN…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 12145 Results