Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-82455 — RubyGems before 4.0.13 Path Traversal via Symlink Resolution

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction ro…

| Path Traversal
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.1 CRITICAL
CVE-2026-82454 — Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from th…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.5 HIGH
CVE-2026-82453 — rust-iot-platform Cleartext Password Storage via User Model

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plain…

Remote | Cryptography
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-82452 — rust-iot-platform Authentication Bypass via Missing Request Guards

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers …

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.1 MEDIUM
CVE-2026-82451 — Formwork through 2.3.14 Stored XSS via Referer Header

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer he…

Remote | Cross-Site Scripting
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.8 HIGH
CVE-2026-82450 — BookStack before 26.05.4 Remote Code Execution via Book Cover

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP pol…

bookstack | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.3 MEDIUM
CVE-2026-82449 — Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across mu…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-82448 — Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Nod…

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child …

Remote | Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.8 HIGH
CVE-2026-82447 — Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. A…

Remote | Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-14494 — Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading …

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamica…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
4.2 MEDIUM
CVE-2026-82364 — macrozheng mall Order Submission submit race condition

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race…

mall | Remote | Race Condition
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-80725 — net: gro: properly validate BIG TCP aggregation criteria

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB)…

linux_kernel | Memory Corruption
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-81346 — Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbit…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-81342 — MasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to re…

masterstudy_lms | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-81200 — MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order bil…

masterstudy_lms | Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-81026 — MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order complete…

masterstudy_lms | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-80488 — WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such…

| Injection
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-80311 — Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation vi…

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-77786 — Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing…

seo | Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
0.0 NA
CVE-2026-77704 — Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing c…

| Authorization
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
Showing 20 of 12130 Results