Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2016-20058 — Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attacker…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20057 — NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary …

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20056 — Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious exe…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20055 — IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a m…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2016-20053 — Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting …

Remote | Cross-Site Request Forgery
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
9.8 CRITICAL
CVE-2016-20052 — Snews CMS 1.7 Unrestricted File Upload via snews_files

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can …

Remote | Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2016-20051 — Snews CMS 1.7 Cross-Site Request Forgery via changeup

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can tric…

Remote | Cross-Site Request Forgery
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2016-20050 — NetSchedScan 1.0 Buffer Overflow Denial of Service

NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can past…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.8 HIGH
CVE-2026-3666 — wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal …

Remote | Path Traversal
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.5 MEDIUM
CVE-2026-3309 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…

Remote | Injection
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2026-2936 — Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.5 HIGH
CVE-2026-1233 — Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated …

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin…

Remote | Information Disclosure
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.4 MEDIUM
CVE-2026-0626 — WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_op…

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all v…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
5.3 MEDIUM
CVE-2025-14938 — Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media …

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is …

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2026-5425 — Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via …

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient …

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.1 HIGH
CVE-2026-3445 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass …

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
4.3 MEDIUM
CVE-2026-2826 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorizati…

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not pr…

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.4 MEDIUM
CVE-2026-2437 — WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+)…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, …

wp_travel_engine | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.1 HIGH
CVE-2026-4896 — WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Aute…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.4 MEDIUM
CVE-2026-2600 — ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored…

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
Showing 20 of 6111 Results