Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-62108 — WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-62104 — WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-62101 — WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-14850 — Weak password recovery mechanism for forgotten password in MobiAPParc

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier …

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.1 MEDIUM
CVE-2026-92932 — MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF …

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition …

Remote | Server-Side Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-92921 — admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords thro…

Remote | Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.4 MEDIUM
CVE-2026-92920 — admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bea…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.1 HIGH
CVE-2026-92919 — admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use …

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-92918 — admin3 through 3.0.0 Session Token Disclosure via Audit Log

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /l…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-92904 — Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoc…

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller'…

satellite satellite | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-81481 — Dell OpenManage Server Administrator Path Traversal Vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker…

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.0 MEDIUM
CVE-2026-92925 — Out-of-Bounds Read in Cluster Bus

In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a…

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-92917 — Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r

Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExt…

grav | Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-92916 — Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoi…

grav | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.3 HIGH
CVE-2026-92915 — WWBN AVideo userVerifyEmail.php Unauthenticated Access Control

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUse…

avideo | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-92914 — AVideo LoginControl PGP Second Factor Authentication Bypass

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session varia…

avideo | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-92913 — AVideo Weak PRNG Activation Code Authentication Bypass

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in …

avideo | Remote | Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.3 HIGH
CVE-2026-92912 — AVideo Cryptographically Weak PRNG via uniqid Stream Key

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibi…

avideo | Remote | Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.4 CRITICAL
CVE-2026-92860 — rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-90823 — FatPipe MPVPN, WARP, and IPVPN Stack-Based Buffer Overflow

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker …

Remote | Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14738 Results