Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-102378 — WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerabili…

Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-100517 — WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object Referen…

Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-100514 — WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnera…

Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2024-58388 — Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path pa…

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.9 CRITICAL
CVE-2026-79901 — Predictable Active Directory service-account passwords in BoKS Manager

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current U…

Remote | Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
3.1 LOW
CVE-2026-66253 — HCL iControl is affected by a Session Timeout vulnerability

iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ab…

icontrol | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
3.1 LOW
CVE-2026-66249 — HCL iControl is affected by a Missing Secure Attribute vulnerability

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extractio…

icontrol | Remote | Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
3.1 LOW
CVE-2026-66248 — HCL iControl is affected by an Improper Error Handling vulnerability

iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive int…

icontrol | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-66247 — HCL iControl is affected by multiple security vulnerabilities

iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabli…

icontrol | Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-66246 — HCL iControl is affected by multiple security vulnerabilities

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege e…

icontrol | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.0 MEDIUM
CVE-2026-103686 — rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting

A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation…

dom-sanitizer | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-102505 — Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from …

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of o…

imager imager | Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-102504 — Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of…

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is si…

imager imager | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.4 MEDIUM
CVE-2026-62063 — WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a …

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-62061 — WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulner…

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Securi…

profilegrid | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-62060 — WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects C…

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-62059 — WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ult…

ultimate_member | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-62058 — WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-103345 — WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103343 — WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14985 Results