Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-81794 — WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vul…

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81793 — WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81791 — WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary Fi…

Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.3 MEDIUM
CVE-2026-81788 — WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

impress_for_idx_broker | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81787 — WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

impress_for_idx_broker | Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81786 — WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Contr…

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81785 — WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

buddyforms | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.1 HIGH
CVE-2026-81784 — WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-81783 — WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulner…

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81782 — WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

wp_docs wp_docs | Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81275 — WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-78536 — WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Contr…

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.6 MEDIUM
CVE-2026-66674 — WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-66632 — WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vulnerability

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-46387 — Suricata http2: decompression bomb can cause denial of service in Suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could gr…

suricata | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-45747 — Suricata lua/tls: null dereference in TlsGetCertInfo

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could derefer…

suricata | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-15461 — Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gn…

zephyr zephyr | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-88009 — Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassin…

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empt…

| Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.1 MEDIUM
CVE-2026-88921 — MISP: Unescaped HTML Injection in PDF Report Element Rendering

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTM…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13962 Results