Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-84753 — WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-84752 — WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

romethemekit_for_elementor | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.3 HIGH
CVE-2026-84736 — Eclipse aeriOS Federator Improper Certificate Validation

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections …

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84238 — WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Co…

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84215 — WordPress Timetics plugin <= 1.0.61 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

wp_timetics | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81776 — WordPress WP QuickLaTeX plugin <= 3.8.8 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81773 — WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81300 — WordPress Calculation For Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulne…

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81295 — WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81292 — WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-81282 — WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scrip…

Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-81281 — WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-75602 — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in Si…

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-suppl…

Remote | Path Traversal
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-85187 — itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate s…

A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=e…

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-63219 — Unauthenticated file upload via missing authorization on formatter upload endpoint

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and all…

| Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-85012 — OS command injection in the Amazon CodeCatalyst blueprints SDK

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-58400 — GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configurat…

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure proc…

| Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-84968 — Heap out-of-bounds read via corrupt nested BSON in field path error message

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory…

php_driver | Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85239 — MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service

A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTe…

misp | Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.6 HIGH
CVE-2026-85238 — Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking

MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authentic…

misp | Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12618 Results