Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-89174 — Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protec…

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts throug…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89173 — Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting…

Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6642 — Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to ins…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6641 — Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input s…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-6640 — Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient in…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-87908 — multiparty vulnerable to Denial of Service via unbounded part-header accumulation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumul…

| Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.5 MEDIUM
CVE-2026-86815 — BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing …

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a …

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-86812 — WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-order…

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allow…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.5 MEDIUM
CVE-2026-86782 — Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite th…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-86781 — SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the Word…

Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.8 MEDIUM
CVE-2026-86780 — Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor t…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
2.7 LOW
CVE-2026-86779 — Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing use…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.8 MEDIUM
CVE-2026-85678 — AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level ac…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-85677 — Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every san…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.8 MEDIUM
CVE-2026-83546 — CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arb…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.8 MEDIUM
CVE-2026-83545 — CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inje…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-82305 — YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change…

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.2 HIGH
CVE-2026-74925 — MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capab…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-73785 — HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-73784 — HPE IceWall products, Remote Bypass of Security Restrictions

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13428 Results