Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-25254 — Improper authorization in Qualcomm Software Center

Improper authorization leads to Remote Code Execution via SocketIO interface.

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-9231 — WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'templa…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template fun…

wp_travel_engine | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.2 HIGH
CVE-2026-95511 — Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial back…

A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged…

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.4 HIGH
CVE-2026-95508 — Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interf…

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP bl…

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.3 HIGH
CVE-2026-93928 — WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vul…

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager f…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.3 CRITICAL
CVE-2026-93556 — Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated aga…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.3 CRITICAL
CVE-2026-89422 — TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_sh…

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the…

erlang\/otp otp | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-68956 — SSH daemon allocates unbounded idle session channels, bypassing max_channels

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are nev…

erlang\/otp otp | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.2 HIGH
CVE-2026-65634 — Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handsha…

erlang\/otp otp | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.9 MEDIUM
CVE-2026-15095 — Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Trave…

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 vi…

Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.3 MEDIUM
CVE-2026-9004 — WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive Information v…

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This m…

Remote | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.8 MEDIUM
CVE-2026-95503 — Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos passwor…

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fail…

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
10.0 CRITICAL
CVE-2026-93952 — Security Advisory 0183

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.2 HIGH
CVE-2026-93836 — WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scriptin…

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input…

wpc_product_bundles_for_woocommerce | Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.2 HIGH
CVE-2026-93778 — WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting via Yelp Revie…

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to…

Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.1 HIGH
CVE-2026-92969 — HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribut…

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter…

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.1 HIGH
CVE-2026-92235 — WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution v…

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an ac…

wp_ultimate_review | Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.3 MEDIUM
CVE-2026-91092 — wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Guest Post T…

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to …

wpforo_forum | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-87082 — Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via…

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, …

| Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-87081 — Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycod…

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and…

| Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 13858 Results