Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-77705 — Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked…

| Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
0.0 NA
CVE-2026-77689 — Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway name…

| Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
0.0 NA
CVE-2026-77006 — WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF …

| Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
0.0 NA
CVE-2026-77005 — Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowi…

| Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
0.0 NA
CVE-2026-75800 — Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log …

| Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.9 CRITICAL
CVE-2026-87719 — Deserialization of Untrusted Data in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user …

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
10.0 CRITICAL
CVE-2026-85706 — GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability - [Actively …

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could…

CISA KEV Remote | Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.3 MEDIUM
CVE-2026-90467 — aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addresses

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft mal…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.4 MEDIUM
CVE-2026-89268 — QloApps through 1.7.0 Reflected XSS via List Filter Parameters

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to s…

qloapps | Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-89267 — starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attac…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-89266 — stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis…

Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.3 MEDIUM
CVE-2026-90461 — OpenStack Ironic Credential Exposure Vulnerability

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

ironic | Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.6 HIGH
CVE-2026-90460 — OpenStack Keystone Improper Access Control Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not …

keystone | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-90457 — Product Credential Store Insecure Password Hash Storage and Improper Access Control

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permission…

| Cryptography
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.2 CRITICAL
CVE-2026-90456 — Inventory Management Component Default Administrative Credential Vulnerability

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into acti…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-90455 — HTTP Client Library Vulnerability Regression in Log-Processing Component

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing compone…

Remote | Supply Chain
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-90454 — Packet-Analysis Component Improper Access Control

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tag…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.1 MEDIUM
CVE-2026-90453 — Web Application Open Redirect Vulnerability

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This al…

Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.0 MEDIUM
CVE-2026-90452 — Identity Provider TLS Certificate Verification Bypass

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker posi…

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.2 HIGH
CVE-2026-90451 — Packet-Analysis Component Authentication Cookie Forgery via Hardcoded Secret

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this ex…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13727 Results