Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-70465 — Fortinet FortiClient Buffer Overflow Vulnerability

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthe…

forticlientwindows | Remote | Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
3.7 LOW
CVE-2026-18044 — Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via S…

The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenti…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-17008 — Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone,…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-16990 — Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attack…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-16747 — Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions

The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticate…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-16621 — Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Pa…

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-15213 — Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callb…

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-15045 — Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvali…

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated c…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certai…

Remote | Supply Chain
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-68868 — Apache Airflow Google provider: google Secret Manager backend: team scope is never applie…

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-67284 — Joomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Clou…

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrit…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.1 MEDIUM
CVE-2026-64955 — Velociraptor CSV Formula Injection in Export Pipeline

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when e…

velociraptor | Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-64952 — Velociraptor Hunt Deletion With Insufficient Permission Check

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE…

velociraptor | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
3.5 LOW
CVE-2026-64951 — Velociraptor DoS triggered by Divide by Zero panic

A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bu…

velociraptor | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.9 MEDIUM
CVE-2026-18663 — 389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext(…

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONT…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.9 MEDIUM
CVE-2026-18652 — Velociraptor STACK Type Download Path Bypasses Denied Prefix Check

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checke…

velociraptor | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.9 MEDIUM
CVE-2026-67283 — Joomla Extension - tabaoca.org - Improper ACL implementation allows allow file operations…

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwr…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
10.0 CRITICAL
CVE-2026-67282 — Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-19566 — Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ra…

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*…

net\ | Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.8 HIGH
CVE-2026-19426 — FitSoft|POS Sytstem - Missing Authentication

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 10919 Results