Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-21065 — Samsung libcodec2secqcelpdec Out-of-Bounds Write

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.0 HIGH
CVE-2026-21064 — Weaver Improper Access Control Vulnerability

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.8 MEDIUM
CVE-2026-21063 — AppLock Improper Component Export Vulnerability

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

android | Authentication
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-64940 — Nishishi Factory Tegalog Authentication Bypass Vulnerability

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log…

| Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
6.8 MEDIUM
CVE-2026-57279 — Cybozu Garoon Cross-Site Scripting Vulnerability

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

garoon | Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
4.8 MEDIUM
CVE-2026-21062 — SemClipboardService Authorization Bypass

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-21061 — Samsung Dialer Improper Input Validation Vulnerability

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

android | Remote | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.7 MEDIUM
CVE-2026-21060 — Samsung Contacts Cross-Profile Data Access Vulnerability

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-21059 — Samsung Contacts Improper Component Export Arbitrary File Deletion Vulnerability

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-21058 — Samsung Contacts Arbitrary File Deletion Vulnerability

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

android | Path Traversal
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-19089 — Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as a…

Remote | Misconfiguration
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
6.5 MEDIUM
CVE-2026-19077 — Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Le…

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Dup…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.0 MEDIUM
CVE-2026-19075 — All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Para…

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`…

all-in-one_video_gallery | Remote | Path Traversal
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.3 MEDIUM
CVE-2026-19074 — Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom …

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX act…

Remote | Information Disclosure
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
9.1 CRITICAL
CVE-2026-19053 — ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter

The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injec…

Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.6 HIGH
CVE-2026-19049 — ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'remove…

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capab…

Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.4 MEDIUM
CVE-2026-18960 — Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the bloc…

Remote | Authentication
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-18946 — Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictab…

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticat…

Remote | Information Disclosure
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
5.5 MEDIUM
CVE-2026-18934 — RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post De…

The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level a…

rss_aggregator_by_feedzy | Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
8.8 HIGH
CVE-2026-18786 — CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose …

Remote | Authentication
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
Showing 20 of 14224 Results