Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-7798 — FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL…

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions…

Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-7636 — Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via RES…

The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. …

Remote | Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-7615 — Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter

The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widge…

Remote | Cross-Site Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-5072 — ptp: Potential Denial of Service via PTP Interval Shift

A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to se…

| Misconfiguration
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.4 MEDIUM
CVE-2026-9104 — Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via Draft Post …

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output esc…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.8 HIGH
CVE-2026-9018 — Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privi…

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` …

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.4 MEDIUM
CVE-2026-7509 — KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Generation ('Cr…

The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` attributes in all versions up to, and including, 4.0.…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-7249 — Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block S…

The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()`…

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.1 MEDIUM
CVE-2026-6864 — CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'page' Parameter

The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sani…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-4070 — Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Parameter

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() fun…

Remote | Cross-Site Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
5.7 MEDIUM
CVE-2026-44409 — Information disclosure vulnerability in ZTE MU5250

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the r…

| Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.1 MEDIUM
CVE-2026-3481 — WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter

The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input saniti…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-2518 — FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Inst…

The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' fun…

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
9.2 CRITICAL
CVE-2026-9054 — Invalid IP packets cause a kernel panic

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.

Remote | Denial of Service
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.9 MEDIUM
CVE-2026-9053 — Apache HTML File Upload Default Path Disclosure

Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.

Remote | Misconfiguration
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.5 HIGH
CVE-2026-4834 — WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplie…

Remote | Injection
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-46598 — Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

| Memory Corruption
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-46597 — Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

| Memory Corruption
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-46595 — Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/s…

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would…

| Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-42508 — Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

| Cryptography
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
Showing 20 of 6121 Results