Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-62645 — Reyrolle 7SR5 Session ID Prediction Vulnerability

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. Th…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.5 HIGH
CVE-2026-58113 — Siemens Teamcenter Reflected Cross-Site Scripting Vulnerability

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All …

teamcenter | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.0 CRITICAL
CVE-2026-50093 — Siemens Siveillance Control Arbitrary File Upload Vulnerability

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < …

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.6 HIGH
CVE-2026-34223 — Siemens Desigo CC Client Code Execution Vulnerability

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All version…

| Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84820 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

unlimited_elements_for_elementor | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84818 — WordPress Open User Map plugin <= 1.4.50 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

open_user_map | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-84817 — WordPress JetFormBuilder plugin <= 3.6.5.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

jetformbuilder | Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.2 HIGH
CVE-2026-81806 — WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerab…

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

hide_my_wp_ghost | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-81802 — WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerabil…

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-81798 — WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4…

Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privi…

Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

product_catalog_mode_for_woocommerce | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-81790 — WordPress Csomagpontok és szállítási címkék WooCommerce-hez plugin < 4.2.8 - Broken Acces…

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csoma…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-81781 — WordPress Unbounce Landing Pages plugin <= 1.1.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: fr…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.2 HIGH
CVE-2026-76561 — Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile co…

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile …

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.4 HIGH
CVE-2026-71375 — XXE Vulnerability in Cosminexus Component Container

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 be…

cosminexus_component_container | Remote | XML External Entity
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-71374 — Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from …

cosminexus_component_container | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-48888 — WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

woocommerce woocommerce | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86519 — code-projects Student Crud Operation Backup File card_activation.sql information disclosu…

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results…

student_crud_operation | Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86518 — code-projects Student Crud Operation edit.php sql injection

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The att…

student_crud_operation | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86517 — itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument I…

sales_and_inventory_system | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12519 Results