Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-9134 — Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1…

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomple…

Remote | Cross-Site Scripting
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.2 HIGH
CVE-2026-9109 — GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translatio…

The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all…

Remote | Cross-Site Scripting
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
0.0 NA
CVE-2026-9062 — Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from…

| Path Traversal
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
0.0 NA
CVE-2026-9061 — Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, all…

| Cross-Site Scripting
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
6.4 MEDIUM
CVE-2026-11769 — Operator - Namespaced User Path Traversal

We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### S…

Remote | Path Traversal
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.5 HIGH
CVE-2026-9848 — WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` f…

Remote | Injection
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
5.5 MEDIUM
CVE-2026-54231 — Abrt: unsanitized systemd journal content written to dump directory files enables content…

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and w…

Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.0 HIGH
CVE-2026-54230 — Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary…

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the t…

Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.0 HIGH
CVE-2026-54229 — Abrt: chownproblemdir succeeds during active post-create event processing due to inadequa…

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files …

Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.8 HIGH
CVE-2026-54228 — Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump …

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can c…

Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
4.9 MEDIUM
CVE-2026-12089 — WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) …

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() …

Remote | Path Traversal
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
4.6 MEDIUM
CVE-2026-11443 — Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User …

Remote | Cross-Site Scripting
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
6.5 MEDIUM
CVE-2026-11442 — Allegra exportReport Directory Traversal Information Disclosure Vulnerability

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authe…

Remote | Path Traversal
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.8 HIGH
CVE-2026-6676 — Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archive

Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may allow Local Execution of Code or Denial-of-Service of the antivirus engine proc…

| Memory Corruption
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
7.4 HIGH
CVE-2026-12068 — Avira Password Manager credential disclosure via cross-origin autofill in Firefox

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the pare…

Remote | Information Disclosure
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
7.8 HIGH
CVE-2025-9033 — Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3)

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This…

| Memory Corruption
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
7.8 HIGH
CVE-2025-9032 — Avira antivirus engine heap buffer OOB read when scanning a malformed PE file

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process…

| Memory Corruption
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
7.8 HIGH
CVE-2025-14098 — Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable …

Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service…

| Memory Corruption
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
5.3 MEDIUM
CVE-2026-54398 — MISP object edit authorization bypass allows unauthorized sharing group assignment

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing …

Remote | Authorization
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
8.7 HIGH
CVE-2026-53868 — Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deleti…

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in…

Remote | Denial of Service
Jun 12, 2026 Jun 12, 2026
Jun 12, 2026
Jun 12, 2026
Showing 20 of 6957 Results