Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-90498 — lenve vhr vhr.sql default credentials

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploi…

vhr | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.0 MEDIUM
CVE-2026-90497 — Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Tas…

feng_office | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.8 MEDIUM
CVE-2026-90496 — Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order s…

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.cla…

feng_office | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-89080 — Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demo…

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who alread…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-88995 — Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve o…

Remote | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.2 MEDIUM
CVE-2026-88912 — rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity P…

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a no…

rtmedia | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.4 MEDIUM
CVE-2026-88764 — Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard s…

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, all…

simple_membership | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.7 LOW
CVE-2026-86407 — User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Members…

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any regi…

Remote | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-86406 — User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership …

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitte…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.7 MEDIUM
CVE-2026-80072 — User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect…

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitor…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.2 HIGH
CVE-2026-80071 — User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authe…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-77773 — Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure…

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthentica…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-90679 — Forgejo ActivityPub Identity Spoofing Vulnerability

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not…

forgejo | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90678 — HAProxy HTTP Request Smuggling Vulnerability

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC b…

haproxy | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90495 — Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection

A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the compone…

feng_office | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90494 — restify node-restify static.js serveStatic path traversal

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be ini…

node-restify | Remote | Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-90493 — Tonec Internet Download Manager Kernel Driver idmwfp.sys access control

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The …

internet_download_manager | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.7 HIGH
CVE-2026-90668 — UnrealIRCd HTTP Header Denial of Service

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unre…

unrealircd | Remote | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90492 — webgjc web_robot web.py controller_recover os command injection

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of …

web_robot | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90491 — sanjevirau gsubs Electron index.js showQuerySuccessPage code injection

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the …

gsubs | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13146 Results