Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-5582 — FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() funct…

Remote | Cross-Site Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.8 MEDIUM
CVE-2026-18382 — Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credent…

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authenticati…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18381 — Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token…

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. T…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18378 — Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfi…

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is s…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.1 HIGH
CVE-2026-17544 — Out-of-bounds write in bccomp() via crafted operand and scale

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

Remote | Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.1 HIGH
CVE-2026-17543 — SQL injection in ext-pgsql via E'...' backslash breakout

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, an…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.2 HIGH
CVE-2026-15397 — Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Man…

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-22622 — Eaton Tripp Lite PADM Improper Input Validation Privilege Escalation

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted acces…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.3 HIGH
CVE-2026-22621 — Eaton Tripp Lite Series PADM OS Command Injection

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restr…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.6 HIGH
CVE-2026-22620 — Eaton Tripp Lite PADM Authentication Bypass Vulnerability

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.8 MEDIUM
CVE-2026-18369 — Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identi…

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a…

enterprise_linux certificate_system enterprise_linux | Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.1 CRITICAL
CVE-2026-18363 — Weak password recovery mechanism in osTicket by Enhancesoft LLC

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the…

osticket | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.9 MEDIUM
CVE-2026-18362 — DFIR-IRIS Missing Brute Force Protection in User Authentication

The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18361 — DFIR-IRIS Stored XSS in Datastore Upload

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

Remote | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18360 — DFIR-IRIS Stored XSS in Custom Attributes

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

Remote | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.9 MEDIUM
CVE-2026-16971 — DFIR-IRIS Missing Brute Force Protection in OTP Validation

The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
4.2 MEDIUM
CVE-2026-16970 — DFIR-IRIS Insufficient Logout Implementation

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

| Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-16969 — DFIR-IRIS Stored XSS in Assets

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.

Remote | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2022-4994 — KVM: x86: wean fast IN from emulator_pio_in

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pi…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-18353 — Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `reque…

Remote | Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 10009 Results