Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-14900 — Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDe…

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitiz…

| Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-4604 — Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary…

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up t…

| Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-16597 — GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fi…

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.2…

| Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.3 MEDIUM
CVE-2026-9720 — Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to Plugin Settin…

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validati…

Remote | Cross-Site Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-65325 — Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate …

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 thro…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-65324 — Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowi…

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 th…

traffic_server | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64557 — Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan…

| Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64556 — perf/core: Detach event groups during remove_on_exec

In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(…

| Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-58156 — Apache Traffic Server: URL and port parsing errors allow access-control bypass

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.3 CRITICAL
CVE-2026-58155 — Apache Traffic Server: Header-name length truncation enables header aliasing and request …

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-58154 — Apache Traffic Server: Memory-safety errors in MIME and header parsing

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,…

traffic_server | Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-58153 — Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients un…

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-58152 — Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 1…

traffic_server | Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-58151 — Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 throu…

traffic_server | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.2 HIGH
CVE-2026-13425 — Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Fi…

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization a…

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.9 MEDIUM
CVE-2026-11973 — WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orde…

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the use…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
10.0 CRITICAL
CVE-2026-58150 — Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing …

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 throu…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
10.0 CRITICAL
CVE-2026-57834 — Apache Traffic Server: Malformed chunked message body allows request smuggling

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 1…

traffic_server | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.3 CRITICAL
CVE-2026-41920 — Apache Traffic Server: SNI to Host header matching policy is not properly enforced

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to …

traffic_server | Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.1 HIGH
CVE-2026-35226 — Out-of-bounds Write in CODESYS PROFINET Controller

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an e…

profinet | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9596 Results