Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-4979 — UsersWP <= 1.2.58 - Authenticated (Subscriber+) Server-Side Request Forgery via 'uwp_crop…

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, an…

userswp | Remote | Server-Side Request Forgery
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.4 MEDIUM
CVE-2026-4895 — Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via disab…

The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.8.9 This is due to insufficient input sanitiz…

greenshift_-_animation_and_page_builder_blocks | Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.4 MEDIUM
CVE-2026-3498 — BlockArt Blocks <= 2.2.15 - Authenticated (Author+) Stored Cross-Site Scripting via 'clie…

The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and including, 2.2.15. This is due to insufficient inpu…

Remote | Cross-Site Scripting
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
4.3 MEDIUM
CVE-2026-3371 — Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbi…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authori…

tutor_lms | Remote | Authorization
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
5.4 MEDIUM
CVE-2026-3358 — Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Pr…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing p…

tutor_lms | Remote | Authorization
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5496 — Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vu…

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5495 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5494 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5493 — Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Executi…

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

| Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
9.8 CRITICAL
CVE-2026-5059 — aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authent…

| Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
9.8 CRITICAL
CVE-2026-5058 — aws-mcp-server Command Injection Remote Code Execution Vulnerability

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication …

| Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5055 — NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attac…

nomachine | Misconfiguration
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-5054 — NoMachine External Control of File Path Local Privilege Escalation Vulnerability

NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker …

nomachine | Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.1 HIGH
CVE-2026-5053 — NoMachine External Control of File Path Arbitrary File Deletion Vulnerability

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker …

nomachine | Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.3 HIGH
CVE-2026-4158 — KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalati…

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o…

keepassxc | Misconfiguration
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4157 — ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of…

home_flex_firmware | Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4156 — ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vuln…

ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installa…

home_flex_firmware | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Discl…

ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected …

home_flex_firmware | Information Disclosure
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4154 — GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4153 — GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
Showing 20 of 6020 Results