Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2023-54346 — WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download

WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file path…

Remote | Information Disclosure
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.8 HIGH
CVE-2023-54345 — Frappe Framework ERPNext 13.4.0 Remote Code Execution

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame intr…

erpnext erpnext | Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
9.8 CRITICAL
CVE-2023-54344 — Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface.…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
9.8 CRITICAL
CVE-2023-54342 — Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the…

Remote | Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-6322 — fast-uri vulnerable to host confusion via percent-encoded authority delimiters

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an…

| Misconfiguration
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2025-42611 — Improper certificate validation in multiple RouterOS services

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x…

routeros | Remote | Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-43870 — Apache Thrift: Node.js web_server.js multi-vulnerability

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'),…

thrift | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.3 MEDIUM
CVE-2026-43868 — Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issu…

thrift | Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-3601 — User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contrib…

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up t…

user_registration_\&_membership | Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-3359 — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unaut…

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due…

form_maker | Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-43869 — Apache Thrift: TSSLTransportFactory.java hostname verification

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixe…

thrift | Misconfiguration
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.9 MEDIUM
CVE-2026-7824 — PaperCut Hive (Ricoh): Plain text password in logs

An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plai…

Remote | Information Disclosure
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.6 MEDIUM
CVE-2026-6418 — PaperCut NG/MF: Path Traversal in Shared Account Synchronization

An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchr…

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.1 MEDIUM
CVE-2026-6180 — PaperCut MF: Card truncation on HP readers

A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence co…

| Race Condition
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-5192 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthent…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path…

forminator | Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
9.3 CRITICAL
CVE-2026-40797 — WordPress WebinarIgnition plugin <= 4.08.253 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: …

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-3454 — GenerateBlocks <= 2.2.0 - Insecure Direct Object Reference to Authenticated (Contributor+…

The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.0. This is due to missing object-level authorization checks in the …

generateblocks | Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.3 MEDIUM
CVE-2026-2729 — Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authori…

The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to p…

forminator | Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
10.0 HIGH
CVE-2026-7823 — Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results…

a8000ru_firmware | Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-7822 — itsourcecode Courier Management System print_pdets.php sql injection

A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The manipulation of the argument ids leads to sql injectio…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
Showing 20 of 5696 Results