Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-32559 — WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

Remote | Misconfiguration
Aug 24, 2026 Aug 25, 2026
Aug 24, 2026
Aug 25, 2026
7.1 HIGH
CVE-2026-32556 — WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 25, 2026
Aug 24, 2026
Aug 25, 2026
9.3 CRITICAL
CVE-2026-32555 — WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability

Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

Remote | Injection
Aug 24, 2026 Aug 25, 2026
Aug 24, 2026
Aug 25, 2026
9.3 CRITICAL
CVE-2026-32554 — WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

Remote | Injection
Aug 24, 2026 Aug 25, 2026
Aug 24, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-27364 — WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

style_kits | Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.0 MEDIUM
CVE-2026-17113 — Cri-o: cri-o: unvalidated image env var causes daemon crash

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). Whe…

openshift_container_platform | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.8 HIGH
CVE-2026-7455 — FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data co…

3ds_max | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.2 CRITICAL
CVE-2026-77635 — CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL…

cakephp | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.2 HIGH
CVE-2026-77634 — CakePHP: SmtpTransport vulnerable to CRLF header injection

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or …

cakephp | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.1 HIGH
CVE-2026-77567 — Filament: App-based MFA can be bypassed when recovery codes are enabled

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-fact…

filament | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
2.3 LOW
CVE-2026-75554 — Explicit organization scopes survive token refresh after membership ends

Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages. expand_repositories_sco…

hexpm | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.3 HIGH
CVE-2026-75542 — OAuth token exchange grants repository scopes for organizations the principal cannot acce…

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API ke…

hexpm | Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-75464 — OneNav Arbitrary File Deletion Vulnerability

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

| Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.8 MEDIUM
CVE-2026-5006 — Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain uni…

vault | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-56136 — NTFS-3G Out-of-Bounds Read Vulnerability

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting …

| Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-56135 — NTFS-3G Heap-Based Buffer Overflow

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g…

| Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.3 MEDIUM
CVE-2026-55468 — Wagtail: Improper restriction handling on Pages admin API

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fie…

wagtail | Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-52492 — LibTiff Heap-Based Buffer Overflow

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow dur…

| Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-52490 — Libtiff Arbitrary Code Execution

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

| Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.8 HIGH
CVE-2026-19568 — SVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds Max

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…

3ds_max | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11592 Results