Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.5 LOW
CVE-2026-96546 — Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ah…

enterprise_linux enterprise_linux | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.4 MEDIUM
CVE-2026-96545 — Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized r…

enterprise_linux enterprise_linux | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96541 — Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake …

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots ind…

enterprise_linux enterprise_linux | Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-95604 — WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-95603 — WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerabili…

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95602 — WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object Refer…

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YI…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.3 CRITICAL
CVE-2026-95601 — WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability

Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-95600 — WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.6 HIGH
CVE-2026-95593 — WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-95592 — WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-95590 — WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability

Subscriber SQL Injection in Tainacan <= 1.2.0 versions.

tainacan | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95586 — WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS…

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

ultimate_addons_for_contact_form_7 | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95530 — WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Sc…

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

pixelyoursite | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-95529 — WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerabi…

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

calculated_fields_form | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-95528 — WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XS…

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95527 — WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95525 — WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability

Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

wp_user_frontend | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-95524 — WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

wp_user_frontend | Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-95523 — WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

wp_user_frontend | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.6 HIGH
CVE-2026-95522 — WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

easy_digital_downloads | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14372 Results