Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-82423 — macrozheng mall Payment Status Endpoint paySuccess behavioral workflow

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of …

mall | Remote | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.5 MEDIUM
CVE-2026-82422 — itsourcecode Sales and Inventory System emp_del.php sql injection

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql …

sales_and_inventory_system | Remote | Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.5 MEDIUM
CVE-2026-82421 — itsourcecode Sales and Inventory System emp_edit.php sql injection

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to…

sales_and_inventory_system | Remote | Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-15369 — Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Esca…

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.5 HIGH
CVE-2026-75807 — SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificat…

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persis…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.3 MEDIUM
CVE-2026-82476 — Memos through 0.30.0 SSRF via Omitted CGNAT Address Range

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers c…

memos | Remote | Server-Side Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.1 HIGH
CVE-2026-82475 — iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow id…

Remote | Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.8 HIGH
CVE-2026-82474 — Sudo through 1.9.17p2 Intercept Policy Bypass via execveat

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by callin…

sudo | Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.2 HIGH
CVE-2026-82473 — KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeed…

kubeedge | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.5 HIGH
CVE-2026-82472 — Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbit…

documenso | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.4 MEDIUM
CVE-2026-82470 — Rodauth before 2.47.0 TOTP Code Reuse via Drift Window

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can …

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.4 MEDIUM
CVE-2026-82469 — Rodauth before 2.47.0 Authentication Bypass via jwt_refresh

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access tok…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
4.7 MEDIUM
CVE-2026-82468 — Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types…

Remote | Cross-Site Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
4.7 MEDIUM
CVE-2026-82467 — Rodauth before 2.47.0 Open Redirect via Return-to Path

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers…

Remote | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.7 HIGH
CVE-2026-82466 — Rodauth before 2.46.0 Authentication Bypass via webauthn_login

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper acco…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.3 MEDIUM
CVE-2026-82465 — pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destr…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.1 MEDIUM
CVE-2026-82464 — pac4j-core before 6.5.6 Open Redirect via Backslash Logout

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft …

pac4j | Remote | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.1 HIGH
CVE-2026-82463 — pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker clie…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.5 MEDIUM
CVE-2026-82462 — pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to crea…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.1 HIGH
CVE-2026-82461 — pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative r…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
Showing 20 of 11979 Results