Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-34964 — Adminer before 5.5.0 SSRF via PDO DSN Injection

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non…

Remote | Server-Side Request Forgery
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.7 MEDIUM
CVE-2026-34959 — Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply …

Remote | Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.3 MEDIUM
CVE-2026-19801 — BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Sho…

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This i…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
2.3 LOW
CVE-2026-16434 — Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefi…

Remote | Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-15023 — Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Param…

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.3 MEDIUM
CVE-2026-10630 — WP Courses LMS <= 3.2.29 - Insecure Direct Object Reference to Authenticated (Custom+) Se…

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.5 HIGH
CVE-2026-66766 — Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection)

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input t…

Remote | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
5.5 MEDIUM
CVE-2026-59183 — OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Deco…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 throu…

| Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.2 MEDIUM
CVE-2026-55373 — OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample cou…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop v…

openexr | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.9 MEDIUM
CVE-2026-55371 — OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL po…

openexr | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.1 MEDIUM
CVE-2026-55059 — OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulner…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bound…

openexr | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NONE
CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil i…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the …

openexr | Remote | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.1 HIGH
CVE-2026-53532 — OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file c…

openexr | Remote | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.7 MEDIUM
CVE-2026-78435 — Faveo Helpdesk Logo SettingsController.php unlink path traversal

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Suc…

helpdesk | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78434 — Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing au…

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component p…

helpdesk | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-78284 — WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

masterstudy_lms | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-78282 — WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-78268 — WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram,…

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

Remote | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-78267 — WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

translatepress | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78266 — WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11547 Results