Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-66733 — Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server pro…

Remote | Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.3 HIGH
CVE-2026-66732 — Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle a…

Remote | Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-65551 — WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.

breakdance | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-19039 — Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection

A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command …

| Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19038 — MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path …

A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element To…

Remote | Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2026-19037 — WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workfl…

A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit Or…

Remote | Race Condition
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.3 HIGH
CVE-2026-19036 — Shibby Tomato wanoptions sub_40F88C os command injection

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command…

tomato | Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.3 LOW
CVE-2026-15599 — Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner

Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5.

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-0673 — Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This i…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.4 MEDIUM
CVE-2026-8166 — Stored XSS in Logo Software's e-Logo Purchasing Portal

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue aff…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-68481 — Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This viola…

cxf | Remote | Cryptography
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.8 CRITICAL
CVE-2026-68079 — Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality.…

cxf | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.1 CRITICAL
CVE-2026-65583 — Apache CXF: Self-issued ID token claims validation skipped

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication…

cxf | Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.1 CRITICAL
CVE-2026-63687 — Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly…

cxf | Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.1 CRITICAL
CVE-2026-61466 — Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it …

cxf | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-5391 — LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-5158 — PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comme…

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to,…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.1 HIGH
CVE-2026-57818 — Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid acces…

cxf | Remote | Race Condition
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.3 HIGH
CVE-2026-19035 — Shibby Tomato qoslimit new_qoslimit_start os command injection

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable le…

tomato | Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-11983 — Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` f…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9989 Results