Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-92905 — Denial of Service Vulnerability

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.

Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.1 HIGH
CVE-2026-57590 — Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cro…

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the pr…

dolphinscheduler | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.1 MEDIUM
CVE-2026-4637 — Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", …

prtg_network_monitor | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-18335 — Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Bl…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data…

Remote | Server-Side Request Forgery
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.4 MEDIUM
CVE-2026-15731 — WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated (Contributor…

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insuf…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.8 CRITICAL
CVE-2026-12227 — Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vc…

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible f…

visual_composer_website_builder | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.8 HIGH
CVE-2026-97185 — Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to…

enterprise_linux enterprise_linux | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-85682 — YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator Account Tak…

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via po…

yop_poll | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-78313 — Improper Access Control in DIAEnergie

Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.1 CRITICAL
CVE-2026-78312 — Path Traversal in DIAEnergie

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-78311 — SQL Injection in DIAEnergie

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-78310 — Authorization Bypass Through User-Controlled Key in DIAEnergie

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-78309 — SQL Injection in DIAEnergie

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.8 CRITICAL
CVE-2026-78308 — Authentication Bypass in DIAEnergie

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

diaenergie | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-77193 — eesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrar…

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for una…

Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-97181 — ezGlobal|GPM LIGHT - Sensitive Data Exposure

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-87739 — PaperCut MF/NG: User permissions are not evaluated on report generation

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials,…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.3 HIGH
CVE-2026-82077 — PaperCut NG/MF: Remote Code Execution via Scan2Fax

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to exec…

Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.9 MEDIUM
CVE-2026-81645 — Graphics Module Out-of-Bounds Read Vulnerability

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
3.8 LOW
CVE-2026-11744 — PaperCut Hive Embedded App for Ricoh: Javascript injection

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process bef…

| Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14287 Results