Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.6 CRITICAL
CVE-2026-12564 — Automation-controller: automation-controller: kubernetes service account token exfiltrati…

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service accou…

ansible_automation_platform | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.5 HIGH
CVE-2026-75898 — RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canv…

ragflow | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-75872 — HTML Injection in MailerUp double opt-in verification email

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
10.0 CRITICAL
CVE-2026-75784 — TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipula…

tew-wlc100 | Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.3 MEDIUM
CVE-2026-75032 — Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetoot…

enterprise_linux enterprise_linux | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-74015 — WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-74012 — WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability

Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.3 MEDIUM
CVE-2026-74009 — WordPress Razorpay for WooCommerce plugin <= 4.8.7 - Insecure Direct Object References (I…

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.3 MEDIUM
CVE-2026-74008 — WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Dat…

Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

shortcodes_and_extra_features_for_phlox_theme | Remote | Information Disclosure
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.3 MEDIUM
CVE-2026-74007 — WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - S…

Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

Remote | Information Disclosure
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-74006 — WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-74004 — WordPress Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms plugin <= 6.0 - …

Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-74003 — WordPress RomethemeForm For Elementor plugin <= 1.2.6 - Broken Access Control vulnerabili…

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-73997 — WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service Attack vuln…

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.8 CRITICAL
CVE-2026-73996 — WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-73995 — WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerability

Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

user_registration | Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-73994 — WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.6 MEDIUM
CVE-2026-73426 — Trix: Stored XSS vulnerability through serialized attributes

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-73404 — WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.1 HIGH
CVE-2026-73400 — WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerabil…

Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 11279 Results