Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-96602 — Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument user…

online-makeup-store | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96601 — Abdurrab5 online-makeup-store Admin Login index.php sql injection

A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/passwor…

online-makeup-store | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.8 CRITICAL
CVE-2026-93352 — Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-86583 — Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege E…

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. T…

import_and_export_users_and_customers | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-81537 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-81536 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

datastage_on_cloud_pak_for_data | Remote | XML External Entity
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-81208 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnera…

datastage_on_cloud_pak_for_data | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-80423 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

datastage_on_cloud_pak_for_data | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-75887 — Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handl…

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` e…

openshift_container_platform | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.1 HIGH
CVE-2026-19125 — EthPress <= 2.3.5 - Unauthenticated Authentication Bypass

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containi…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96556 — Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization

A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role…

cafemanagement | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.6 HIGH
CVE-2026-82369 — Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a

Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An…

sannav sannav | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-80425 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-80412 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-80379 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-75886 — Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalog…

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshif…

openshift_container_platform | Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-6935 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local syste…

concert | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.8 CRITICAL
CVE-2026-6928 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memor…

concert | Remote | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-6925 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to…

concert | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-6794 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary cod…

concert | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14353 Results