Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-27749 — Avira Internet Security System Speedup Insecure Deserialization

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privi…

Mar 05, 2026 Apr 01, 2026
Mar 05, 2026
Apr 01, 2026
8.5 HIGH
CVE-2026-27748 — Avira Internet Security Arbitrary File Deletion via Improper Link Resolution

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:…

Mar 05, 2026 Apr 01, 2026
Mar 05, 2026
Apr 01, 2026
7.5 HIGH
CVE-2025-69534 — Python-Markdown HTML Injection Denial of Service

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-M…

markdown | Remote | Denial of Service
Mar 05, 2026 Mar 13, 2026
Mar 05, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-1720 — WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <=…

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability…

Remote | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-2599 — Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Obje…

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input…

Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
Showing 20 of 6085 Results