Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-24552 — WordPress Create by Mediavine plugin <= 2.5.3 - SQL Injection vulnerability

Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.

create | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-24537 — WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSR…

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

wp_accessibility_helper | Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.9 MEDIUM
CVE-2025-68081 — WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-64611 — Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1…

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sus…

enterprise_linux enterprise_linux | Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-16745 — Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without o…

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impe…

openshift_ai | Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.2 HIGH
CVE-2026-65758 — Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5…

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefo…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.1 HIGH
CVE-2026-65757 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users with…

Remote | Authorization
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
6.1 MEDIUM
CVE-2026-65756 — Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-65755 — Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywh…

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Ca…

| Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-65754 — Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

| XML External Entity
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-65713 — Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

Remote | Path Traversal
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
6.2 MEDIUM
CVE-2026-65712 — Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extensi…

Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modif…

| Path Traversal
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
0.0 NA
CVE-2026-65431 — Joomla Extension - regularlabs.com - Zipslip in GeoIP extension

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

| Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-65430 — Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

| Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-64876 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks i…

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause u…

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-64875 — Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

| Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-64874 — Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

| Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-64873 — Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

Remote | Server-Side Request Forgery
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-64872 — Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

Remote | Path Traversal
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
5.4 MEDIUM
CVE-2026-64871 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-manag…

Remote | Authentication
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
Showing 20 of 8923 Results