Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-4945 — Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification By…

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.4 MEDIUM
CVE-2026-12853 — Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Ta…

The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perf…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51018 — PocketMine-MP before 3.26.5 Input Validation via Book Pages

PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs…

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2022-51017 — PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can …

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.1 MEDIUM
CVE-2022-51016 — PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login t…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51015 — PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket

PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket). …

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51014 — PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding

PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form …

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51013 — PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemsta…

Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51012 — PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions wi…

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2022-51011 — PocketMine-MP before 4.2.10 Denial of Service via Chat Messages

PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many ne…

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2022-51010 — PocketMine-MP before 4.4.2 Server Crash via Item ID

PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught …

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86404 — Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging…

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via i…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.0 MEDIUM
CVE-2026-86301 — code-projects Hospital Information System Patient Management editPatient.php cross site s…

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Suc…

hospital_information_system | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86300 — Tenda AC9 Web Management R7WebsSecurityHandler improper authentication

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be in…

ac9 | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.9 CRITICAL
CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of …

re7000 | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.9 MEDIUM
CVE-2026-78325 — XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a…

| Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.4 MEDIUM
CVE-2026-2390 — Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Loa…

The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_pro…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.1 MEDIUM
CVE-2026-86351 — MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacke…

Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86298 — SourceCodester Class and Exam Timetabling System delete_subject.php sql injection

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument…

class_and_exam_timetabling_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.2 HIGH
CVE-2026-86297 — D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Pa…

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12487 Results