Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-59248 — Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a deni…

cowlib | Remote | Denial of Service
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
4.3 MEDIUM
CVE-2026-58246 — Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABA…

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with …

| Information Disclosure
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
9.8 CRITICAL
CVE-2026-16462 — SQL injection via unauthenticated GetGridData endpoint

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-14785 — Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user sup…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-14328 — Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_g…

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insu…

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
9.4 CRITICAL
CVE-2026-11841 — CVE-2026-11841

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem direc…

Remote | Misconfiguration
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.0 MEDIUM
CVE-2026-11598 — Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name…

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-10207 — PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.8 MEDIUM
CVE-2026-9680 — MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interface…

Remote | Misconfiguration
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.1 MEDIUM
CVE-2026-8167 — Reflected XSS in theWP's News Theme V8

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: th…

Remote | Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.6 HIGH
CVE-2026-61376 — ELECOM Wireless LAN Routers and Access Points OS Command Injection Vulnerability

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by…

Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.6 HIGH
CVE-2026-59764 — ELECOM Wireless LAN Routers and Access Points OS Command Injection Vulnerability

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacke…

| Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.2 MEDIUM
CVE-2026-44387 — ELECOM Wireless LAN Routers and Access Points Reflected Cross-Site Scripting Vulnerability

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a log…

wab-i1750-ps wab-s1167-ps | Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.5 MEDIUM
CVE-2026-15267 — Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-14516 — Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 d…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.1 MEDIUM
CVE-2026-14171 — ads-tec Industrial IT: Post-login open redirect in the web interface

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and …

Remote | Cross-Site Request Forgery
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.1 HIGH
CVE-2026-14169 — ads-tec Industrial IT: Account lockout via non-atomic user creation

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete admin…

Remote | Race Condition
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-14168 — ads-tec Industrial IT: Vertical privilege escalation via configuration table write

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-14167 — ads-tec Industrial IT: Privilege escalation during configuration import

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-13161 — TrueBooker <= 1.2.2 - Unauthenticated SQL Injection

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
Showing 20 of 9379 Results