Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-2128 — Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthori…

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wo…

Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.3 MEDIUM
CVE-2026-8995 — Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure i…

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient acc…

Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.4 MEDIUM
CVE-2026-7430 — Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Scripting via …

The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet conte…

post_snippets | Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.3 HIGH
CVE-2026-8070 — ASUS Armoury Crate Local Privilege Escalation

Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical m…

armoury_crate | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.3 HIGH
CVE-2026-7480 — ASUS System Control Interface Privilege Escalation Remote Code Execution Vulnerability

An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RP…

system_control_interface | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.1 MEDIUM
CVE-2026-6892 — Canon CUPS Printer Driver for macOS Symbolic Link Privilege Escalation

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installat…

| Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.1 MEDIUM
CVE-2026-6891 — My Image Garden Local File Permission Manipulation Vulnerability

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic lin…

| Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 7387 Results