Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-8791 — Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capabilit…

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.4 MEDIUM
CVE-2026-7436 — WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross…

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and inc…

wpc_badge_management_for_woocommerce | Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.9 MEDIUM
CVE-2026-6089 — WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery

The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the …

Remote | Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
10.0 CRITICAL
CVE-2026-65883 — Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Les…

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code executi…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.5 MEDIUM
CVE-2026-5060 — MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure …

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is du…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.6 MEDIUM
CVE-2026-56390 — Arbitrary Output Location Change in GNU Bison

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑suppl…

bison | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.8 MEDIUM
CVE-2026-56389 — Arbitrary Command Execution in GNU Bison

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable…

bison | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.8 MEDIUM
CVE-2026-50642 — Terminal Escape Injection in diff‑so‑fancy

diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, includ…

| Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-4604 — Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary…

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up t…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.8 HIGH
CVE-2026-18220 — Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto st…

Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.2 HIGH
CVE-2026-16655 — Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in…

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.2 HIGH
CVE-2026-16597 — GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fi…

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.2…

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-14900 — Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDe…

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitiz…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.1 CRITICAL
CVE-2026-14488 — Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion …

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.1 HIGH
CVE-2026-12895 — SQL Injection in Frappe's ERPNext

SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing par…

erpnext | Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-65100 — Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed heade…

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and cor…

traffic_server | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-59243 — Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by def…

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callb…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-58189 — Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 t…

traffic_server | Remote | Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.4 HIGH
CVE-2026-58188 — Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.…

traffic_server | Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-58187 — Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from …

traffic_server | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9627 Results