Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-73056 — SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.To…

Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-72888 — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of…

Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound an…

| Memory Corruption
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently d…

Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.…

| Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from …

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO sessi…

| Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.7 HIGH
CVE-2024-58375 — OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As …

Remote | Misconfiguration
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.3 CRITICAL
CVE-2026-74251 — Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoc…

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public s…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-74578 — crypto: algif_skcipher - force synchronous processing on trees without ctx->state

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() passes…

linux_kernel | Cryptography
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2024-13784 — Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP …

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted i…

arforms_form_builder | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-2497 — Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image…

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insu…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-2357 — Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient in…

bold_page_builder | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-18347 — Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informati…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not p…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-17608 — WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or in…

wp_compress | Remote | Cross-Site Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.9 MEDIUM
CVE-2026-17604 — Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data'…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter paramete…

Remote | Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-17087 — WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Informatio…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin n…

wp_travel_engine | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-13424 — Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-S…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, an…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.3 MEDIUM
CVE-2026-12998 — Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensit…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the '…

forminator | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-10734 — Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record …

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization…

infility_global | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-9767 — The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' …

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insuffi…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.9 MEDIUM
CVE-2026-2283 — User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' …

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user su…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19934 — itsourcecode Hospital Management System vieworder.php sql injection

A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injecti…

hospital_management_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
Showing 20 of 11257 Results