Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-16959 — Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with …

| Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-16577 — Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance w…

| Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-16576 — Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a…

| Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-16575 — Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticat…

| Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-14601 — Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to per…

| Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-14325 — Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via d…

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users w…

| Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-13736 — NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII …

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email …

| Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2025-15671 — Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an …

| Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-65645 — Rocket.Chat Insecure DDP Method Schema Validation Information Disclosure

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped param…

| Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-65644 — Rocket.Chat Cross-Site Scripting Vulnerability

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized n…

| Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-45202 — GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`

Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintain…

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-45201 — GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read…

Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to imprope…

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and…

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.2 HIGH
CVE-2026-18409 — WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text…

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficien…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.3 CRITICAL
CVE-2026-76158 — Datiphy Data Management Center - External Control of File Name or Path

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside th…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.8 MEDIUM
CVE-2026-76137 — VOCALOID6 Local Privilege Escalation Vulnerability

Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges vi…

| Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.9 MEDIUM
CVE-2026-76131 — Yamaha VOCALOID6 Hard-Coded Credentials Vulnerability

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.

| Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.7 HIGH
CVE-2026-73267 — Clusterclaims-controller: clusterclaims-controller: managedcluster deletion keyed solely …

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulatin…

multicluster_engine_for_kubernetes | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.5 MEDIUM
CVE-2026-77392 — SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser…

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of th…

Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.0 MEDIUM
CVE-2026-77391 — SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-site request …

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forg…

Remote | Cross-Site Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
Showing 20 of 11750 Results