Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-47233 — Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incompl…

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied t…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-71408 — Fortinet FortiOS Resource Exhaustion Denial of Service Vulnerability

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of servic…

fortios fortios | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.6 MEDIUM
CVE-2026-71407 — Fortinet FortiOS Stack-based Buffer Overflow

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute a…

fortios fortiproxy fortios fortipam | Remote | Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.1 HIGH
CVE-2026-70468 — Fortinet FortiManager Authentication Bypass Vulnerability

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, …

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
3.8 LOW
CVE-2026-70467 — Fortinet FortiSIEM Server-Side Request Forgery Vulnerability

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, F…

fortisiem | Remote | Server-Side Request Forgery
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-70466 — Fortinet FortiWeb Improper Access Control

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all ver…

fortios fortiweb fortios | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.3 CRITICAL
CVE-2026-57858 — Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary Java…

Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.3 HIGH
CVE-2026-53996 — NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SETCONFIG ioctl

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without ele…

| Race Condition
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-47226 — Admidio: Authorization bypass in file_delete enables cross-folder file removal by authent…

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they …

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.8 CRITICAL
CVE-2026-26035 — Fortinet FortiWeb Improper Authentication Vulnerability

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, …

fortiweb | Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.4 MEDIUM
CVE-2026-70560 — Ultimate POS Stored XSS via First Name Field in Leave Notifications

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by s…

Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.1 HIGH
CVE-2026-70465 — Fortinet FortiClient Buffer Overflow Vulnerability

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthe…

forticlientwindows | Remote | Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
3.7 LOW
CVE-2026-18044 — Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via S…

The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenti…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-17008 — Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone,…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-16990 — Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attack…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-16747 — Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions

The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticate…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-16621 — Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Pa…

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-15213 — Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callb…

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-15045 — Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvali…

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated c…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certai…

Remote | Supply Chain
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 10856 Results