Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-4671 — justhtml before 1.18.0 Denial of Service via CSS Selector

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query()…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.9 CRITICAL
CVE-2026-78155 — Untrusted Search Path in StackGres

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.5 MEDIUM
CVE-2026-78115 — SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.ph…

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. …

class_and_exam_timetabling_system | Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78112 — itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection

A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes …

Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
8.5 HIGH
CVE-2026-10053 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authentic…

gitlab | Remote | Path Traversal
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
4.3 MEDIUM
CVE-2026-77116 — Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.1 HIGH
CVE-2026-77115 — Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
2.7 LOW
CVE-2026-77003 — Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_conte…

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and p…

content_mask | Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
4.3 MEDIUM
CVE-2026-14853 — WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Au…

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with S…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-13598 — RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain…

| Authentication
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.4 HIGH
CVE-2026-78063 — Tenda CH22 editFileName formeditFileName command injection

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results…

ch22_firmware ch22 | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-78062 — vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of …

taxhacker | Remote | Misconfiguration
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78061 — vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation…

taxhacker | Remote | Server-Side Request Forgery
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78060 — SourceCodester Stock Management System getOrderReport.php cross site scripting

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argume…

stock_management_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78059 — SourceCodester Stock Management System printOrder.php cross site scripting

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientN…

stock_management_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78057 — sambitraj Student-Management-System Management Mutation sql injection

A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulati…

student-management-system | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78056 — sambitraj Student-Management-System Dashboard sql injection

A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. Th…

student-management-system | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78055 — SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.8 HIGH
CVE-2026-78136 — CHIRP Eval Injection

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78054 — SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lea…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
Showing 20 of 11459 Results