Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7633 — Totolink N300RH cstecgi.cgi setUploadSetting file inclusion

A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7632 — code-projects Online Hospital Management System viewappointment.php sql injection

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-7631 — code-projects Online Hospital Management System Registration improper authorization

A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument U…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7630 — innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper auth…

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of …

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7629 — kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool comm…

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.3 MEDIUM
CVE-2026-3504 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/…

Remote | Information Disclosure
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
8.1 HIGH
CVE-2026-2554 — WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compati…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.4 MEDIUM
CVE-2026-0703 — NextMove Lite - Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) S…

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and includ…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7628 — crazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.8 MEDIUM
CVE-2026-6817 — Quiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_rea…

The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input saniti…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-6525 — NULL Pointer Dereference in Wireshark

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

| Denial of Service
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-6320 — Salon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via…

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.4 MEDIUM
CVE-2026-4790 — Premium Addons for Elementor <= 4.11.70 - Authenticated (Contributor+) Stored Cross-Site …

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and inclu…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.1 HIGH
CVE-2026-4100 — Paid Memberships Pro <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Stri…

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to mis…

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-4062 — Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Paramet…

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to in…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-4061 — Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Para…

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-4060 — Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7627 — 8nite metatrader-4-mcp sync_ea_from_file index.ts CallToolRequestSchema path traversal

A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. …

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.8 MEDIUM
CVE-2026-7612 — itsourcecode Courier Management System edit_user.php sql injection

A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql i…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.3 MEDIUM
CVE-2026-7611 — TRENDnet TEW-821DAP Firmware Update cameo_dev.sh platform_do_upgrade_cameo_dev data authe…

A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a…

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
Showing 20 of 5640 Results