Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-90511 — GongShengyue OnlineBooks listSplit BooksServlet.java sql injection

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.jav…

onlinebooks | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.3 HIGH
CVE-2026-90510 — dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-v…

orion-visor | Remote | Cryptography
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90509 — dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded crede…

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation ca…

orion-visor | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.4 LOW
CVE-2026-90508 — Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallbac…

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the …

ludashi | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90507 — vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the c…

warp-clash-api | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2026-90506 — vvbbnn00 WARP-Clash-API Save Account Job race condition

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes …

warp-clash-api | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2026-90505 — vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The atta…

warp-clash-api | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90504 — vvbbnn00 WARP-Clash-API authorized missing authentication

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY …

warp-clash-api | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.3 LOW
CVE-2026-90503 — Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure

A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument Phy…

ludashi | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.0 MEDIUM
CVE-2026-90502 — stilleshan ServerStatus Stats Generation main.cpp cross site scripting

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the ar…

serverstatus | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90501 — lenve vhr HrMapper.xml HrInfoController.updateHr privileges management

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password le…

vhr | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90500 — lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the…

vhr | Remote | Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90499 — lenve vhr Password Update pass HrInfoController.updatePass improper authorization

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of…

vhr | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90498 — lenve vhr vhr.sql default credentials

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploi…

vhr | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.0 MEDIUM
CVE-2026-90497 — Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Tas…

feng_office | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.8 MEDIUM
CVE-2026-90496 — Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order s…

A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.cla…

feng_office | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-89080 — Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demo…

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who alread…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-88995 — Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve o…

Remote | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.2 MEDIUM
CVE-2026-88912 — rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity P…

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a no…

rtmedia | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.4 MEDIUM
CVE-2026-88764 — Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard s…

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, all…

simple_membership | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13153 Results