Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-42249 — Remote Code Execution in Ollama via Update Mechanism

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the applicat…

| Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.7 HIGH
CVE-2026-42248 — Missing Signature Verification for Updates in Ollama

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unco…

| Supply Chain
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2026-22745 — CVE-2026-22745 : Denial of service in static resource handling on Windows platforms

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: …

Remote | Denial of Service
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NONE
CVE-2026-22741 — Static resource cache poisoning in Spring MVC and WebFlux

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the ap…

Remote | Misconfiguration
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2026-2902 — WP Meteor Website Speed Optimization Addon <= 3.4.16 - Unauthenticated Stored Cross-Site …

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frontend_rewrite' function's 'WPMETEOR[N]WPMETEOR' placeholder content in all…

| Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NONE
CVE-2026-22740 — Spring Framework DoS with Multipart Temp Files in WebFlux

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully pr…

Remote | Denial of Service
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.4 MEDIUM
CVE-2026-42641 — WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerabil…

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

Remote | Server-Side Request Forgery
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.3 MEDIUM
CVE-2026-42645 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.11.0 - Cross Site Re…

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders al…

Remote | Cross-Site Request Forgery
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.3 MEDIUM
CVE-2026-42648 — WordPress Spectra plugin <= 2.19.22 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from …

Remote | Authorization
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2026-42642 — WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.

Remote | Authorization
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.6 HIGH
CVE-2026-42646 — WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.9 MEDIUM
CVE-2026-42643 — WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a t…

Remote | Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2026-42644 — WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: fr…

Remote | Information Disclosure
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2026-42652 — WordPress User Registration plugin <= 5.1.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Regist…

Remote | Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2026-4019 — Complianz – GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated …

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/co…

Remote | Authorization
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.7 HIGH
CVE-2026-42518 — Information Disclosure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vu…

Remote | Cryptography
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2026-42517 — Cryptographic Failure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulat…

Remote | Cryptography
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2026-42516 — Broken Access Control Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in th…

Remote | Authorization
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2026-42515 — Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API re…

Remote | Authorization
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-42514 — Sensitive Data Exposure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTP…

Remote | Information Disclosure
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
Showing 20 of 5933 Results