Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-24962 — WordPress Sigmize plugin <= 0.0.9 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through <= 0.0.9.

Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-24961 — WordPress Grand Blog theme < 3.1.5 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.

Remote | Server-Side Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24958 — WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElem…

jetelements_for_elementor | Remote | Cross-Site Scripting
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24957 — WordPress Strong Testimonials plugin <= 3.2.20 - Broken Access Control vulnerability

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials:…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
8.8 HIGH
CVE-2026-24954 — WordPress WpEvently plugin <= 5.0.8 - Deserialization of untrusted data vulnerability

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24952 — WordPress Seriously Simple Podcasting plugin <= 3.14.1 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue…

seriously_simple_podcasting | Remote | Cross-Site Scripting
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24951 — WordPress myCred plugin <= 2.9.7.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24947 — WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vu…

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA…

element_kit_for_elementor | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
5.3 MEDIUM
CVE-2026-24945 — WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.34 - Broken Access Control vul…

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

ultimate_addons_for_contact_form_7 | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24942 — WordPress WpEvently plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.

event_manager_and_tickets_selling_for_woocommerce | Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24940 — WordPress Travelfic Toolkit plugin <= 1.3.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelfic Toolkit: from …

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24939 — WordPress Modula Image Gallery plugin <= 2.13.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image G…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
5.9 MEDIUM
CVE-2026-24938 — WordPress Better Search plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search better-search allows Stored XSS.This issue affects Better Search: from n/a thr…

better_search | Remote | Cross-Site Scripting
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
7.5 HIGH
CVE-2026-1814 — Rapid7 Nexpose Insecure Java Keystore Password Generation

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, t…

Remote | Cryptography
Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-1312 — Potential SQL injection via QuerySet.order_by and FilteredRelation

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, …

django | Remote | Injection
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
5.4 MEDIUM
CVE-2026-1287 — Potential SQL injection in column aliases via control characters

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafte…

django | Remote | Injection
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
7.5 HIGH
CVE-2026-1285 — Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_…

django | Remote | Denial of Service
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
5.4 MEDIUM
CVE-2026-1207 — Potential SQL injection via raster lookups on PostGIS

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the ba…

django | Remote | Injection
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
8.2 HIGH
CVE-2025-65017 — Decidim's private data exports can lead to data leaks

Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generat…

decidim | Remote | Information Disclosure
Feb 03, 2026 Feb 23, 2026
Feb 03, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2025-5319 — SQLi in Emit Informatics' DIGITA Efficiency Management System

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Man…

Remote | Injection
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
Showing 20 of 5264 Results