Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-83545 — CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inje…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-82305 — YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change…

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.2 HIGH
CVE-2026-74925 — MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capab…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-73785 — HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.8 HIGH
CVE-2026-73784 — HPE IceWall products, Remote Bypass of Security Restrictions

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.3 MEDIUM
CVE-2026-14566 — Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tamper…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowin…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.4 MEDIUM
CVE-2026-14565 — Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configura…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values …

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-14563 — Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-14562 — Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded atta…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
10.0 CRITICAL
CVE-2026-14560 — Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unaut…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-14559 — Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, includ…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-13326 — Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt N…

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

| Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.5 LOW
CVE-2025-15695 — GTranslate < 3.0.10 - Admin+ Stored XSS

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as h…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.1 MEDIUM
CVE-2026-89169 — live-boot dm-verity Security Bypass

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

| Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
2.9 LOW
CVE-2026-89162 — PCRE2 Information Disclosure Vulnerability

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

pcre2 | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.7 HIGH
CVE-2026-89060 — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicl…

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder…

Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-8778 — MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Up…

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.4 HIGH
CVE-2026-89161 — PCRE2 Memory Corruption Vulnerability

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

pcre2 | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.7 LOW
CVE-2026-89160 — PCRE2 Out-of-Bounds Read

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

pcre2 | Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-89158 — PCRE2 Integer Overflow and Out-of-Bounds Write

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

pcre2 | Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13405 Results