Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-1620 — Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion v…

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name p…

Remote | Path Traversal
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-1572 — Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+…

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0…

Remote | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2025-13364 — WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4…

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.5 HIGH
CVE-2026-5050 — Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Improper Verification of Cryptog…

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_requ…

Remote | Cryptography
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.5 MEDIUM
CVE-2026-3773 — Accessibility Suite by Ability, Inc <= 4.20 - Authenticated (Subscriber+) SQL Injection v…

The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.20. This is due to insufficient escapin…

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.8 HIGH
CVE-2026-3614 — AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privile…

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router`…

Remote | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.5 HIGH
CVE-2026-3599 — Riaxe Product Customizer <= 2.1.2 - Unauthenticated SQL Injection via 'options' Parameter…

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST …

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-3596 — Riaxe Product Customizer <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Op…

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopr…

Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.3 MEDIUM
CVE-2026-3595 — Riaxe Product Customizer <= 2.1.2 - Unauthenticated Arbitrary User Deletion via 'user_id'…

The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp…

Remote | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.3 MEDIUM
CVE-2026-3581 — Basic Google Maps Placemarks <= 1.10.7 - Missing Authorization to Unauthenticated Default…

The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is a…

Remote | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.4 MEDIUM
CVE-2026-3551 — Custom New User Notification <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site …

The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insuffic…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.8 HIGH
CVE-2026-22619 — Eaton Intelligent Power Protector Remote Code Execution Vulnerability

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. Thi…

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.9 MEDIUM
CVE-2026-22618 — Eaton Intelligent Power Protector Insecure HTTP Response Header Vulnerability

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attack…

Remote | Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.7 MEDIUM
CVE-2026-22617 — Eaton Intelligent Power Protector Cookie Insecure Storage

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. Th…

Remote | Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.3 MEDIUM
CVE-2026-40118 — Arcserve UDP Console Information Disclosure Vulnerability

UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product t…

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.5 MEDIUM
CVE-2026-22616 — Eaton Intelligent Power Protector Web Authentication Brute Force

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been …

Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.0 MEDIUM
CVE-2026-22615 — Eaton Intelligent Power Protector Remote Command Execution Vulnerability

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious cod…

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.3 MEDIUM
CVE-2023-5872 — Wago: Vulnerability in Smart Designer Web-Application

In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.

Remote | Information Disclosure
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.8 HIGH
CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions

In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, i…

Remote | Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-5070 — Vantage <= 1.20.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery…

The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the galler…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
Showing 20 of 6548 Results