Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-14293 — Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output o…

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
4.1 MEDIUM
CVE-2026-14238 — Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report

The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing u…

Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-14237 — Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
3.8 LOW
CVE-2026-14211 — Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allo…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-14206 — HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
4.8 MEDIUM
CVE-2026-13701 — Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-13600 — AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-…

Remote | Authentication
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-13170 — Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include an…

Remote | Path Traversal
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.4 HIGH
CVE-2026-13133 — LINE for Windows DLL Hijacking Vulnerability

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious…

line | Misconfiguration
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
2.2 LOW
CVE-2026-12971 — LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featu…

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arb…

learnpress | Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.5 MEDIUM
CVE-2026-12570 — Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.…

keras | Denial of Service
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
6.2 MEDIUM
CVE-2026-72522 — libexpat Out-of-Bounds Read and Infinite Loop

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

libexpat | Memory Corruption
Aug 10, 2026 Aug 31, 2026
Aug 10, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-19389 — Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemu…

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficie…

enterprise_linux enterprise_linux libefiboot | Remote | Memory Corruption
Aug 10, 2026 Aug 18, 2026
Aug 10, 2026
Aug 18, 2026
7.6 HIGH
CVE-2026-19387 — Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec i…

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi…

enterprise_linux grub2 enterprise_linux libefiboot | Remote | Memory Corruption
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-19384 — SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulati…

simple_doctors_appointment_system | Remote | Injection
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
5.8 MEDIUM
CVE-2026-19383 — saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload En…

saiadmin saiadmin | Remote | Path Traversal
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
2.3 LOW
CVE-2026-19382 — Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to m…

speedfan | Memory Corruption
Aug 10, 2026 Aug 13, 2026
Aug 10, 2026
Aug 13, 2026
7.8 HIGH
CVE-2026-19381 — Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performin…

Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
2.3 LOW
CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of referen…

wireguard.sys | Memory Corruption
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-19379 — EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os co…

iptime_ax8004m | Remote | Injection
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
Showing 20 of 13949 Results