Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.7 MEDIUM
CVE-2026-21423 — Dell PowerScale OneFS Default Permissions Vulnerability

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could p…

powerscale_onefs powerscale_onefs | Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.7 MEDIUM
CVE-2026-21422 — Dell PowerScale OneFS External Control of System Setting Vulnerability

Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1, contains an external control of system or configuration setting vulnerability. A high privileged atta…

powerscale_onefs powerscale_onefs | Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.7 MEDIUM
CVE-2026-21421 — Dell PowerScale OneFS Privilege Escalation Vulnerability

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access…

Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-3058 — Seraphinite Accelerator <= 2.28.14 - Authenticated (Subscriber+) Exposure of Sensitive In…

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via the `seraph_accel_api` AJAX action with `fn=GetData`…

seraphinite_accelerator | Remote | Information Disclosure
Mar 04, 2026 Mar 31, 2026
Mar 04, 2026
Mar 31, 2026
4.3 MEDIUM
CVE-2026-3056 — Seraphinite Accelerator <= 2.28.14 - Missing Authorization to Authenticated (Subscriber+)…

The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all v…

seraphinite_accelerator | Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.4 MEDIUM
CVE-2026-2355 — My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cro…

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template` attribute of the `[my_calendar_upcoming]` shortcode in all versions up …

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-1674 — Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Bu…

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization…

Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
Showing 20 of 6347 Results