Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-13693 — Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attacke…

bit_form | Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-11767 — CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthent…

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-3182 — Sensitive Data Exposure

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

manageengine_endpoint_central | Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-16266 — mongo-object Prototype Pollution Vulnerability

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a c…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.8 MEDIUM
CVE-2026-15927 — Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url val…

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, …

quay mirror_registry_for_red_hat_openshift | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.8 MEDIUM
CVE-2026-15812 — Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dyna…

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting …

Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.8 MEDIUM
CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration…

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes t…

Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
4.9 MEDIUM
CVE-2026-15782 — WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMo…

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration dat…

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-13439 — Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Admi…

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password r…

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2023-37507 — An information disclosure vulnerability affects HCL DevOps Plan

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

devops_plan | Remote | Information Disclosure
Jul 21, 2026 Jul 29, 2026
Jul 21, 2026
Jul 29, 2026
6.4 MEDIUM
CVE-2026-15156 — Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions…

essential_addons_for_elementor | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2023-37508 — HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

devops_plan | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 29, 2026
Jul 21, 2026
Jul 29, 2026
7.0 HIGH
CVE-2026-59776 — FeliCa IC Chips Missing Cryptographic Step Vulnerability

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tam…

| Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.3 MEDIUM
CVE-2026-16336 — trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing…

trino | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.2 HIGH
CVE-2026-6952 — Zyxel AX7501-B1 Command Injection Vulnerability

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attac…

ax7501-b1_firmware | Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.8 MEDIUM
CVE-2026-63729 — TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash appli…

tex_live | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-16334 — itsourcecode Hospital Management System prescriptionorder.php sql injection

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid lea…

hospital_management_system | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-16332 — D-Link DNS-320 multi_uploadify.php unrestricted upload

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrest…

dns-320_firmware | Remote | Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-16331 — D-Link DNS-320 save_ajax.php unrestricted upload

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads…

dns-320_firmware | Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-16330 — D-Link DNS-320 uploadify.php unrestricted upload

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n92…

dns-320_firmware | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 9586 Results