Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-4805 — Woostify <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js …

The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient input sanitization and output escaping in the bundle…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-41526 — KDE KCoreAddons Shell Injection Vulnerability

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading …

| Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-41525 — KDE Dolphin Flatpak Sandbox Escalation Vulnerability

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of …

| Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.9 MEDIUM
CVE-2026-40966 — VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltr…

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conv…

spring_ai | Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.7 HIGH
CVE-2024-54013 — Authentication Bypass

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to prot…

| Authorization
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.5 HIGH
CVE-2024-54012 — Command Injection

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be e…

| Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.3 MEDIUM
CVE-2024-54011 — Missing Error/Exception Handling

Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has r…

Remote | Denial of Service
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7234 — BrowserOperator browser-operator-core server.js startsWith path traversal

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of th…

Remote | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
3.3 LOW
CVE-2026-7233 — Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulatio…

mupdf | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.3 MEDIUM
CVE-2026-7230 — SourceCodester Safety Anger Pad cross site scripting

A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attac…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-7229 — code-projects Coaching Management System POST reply.php sql injection

A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manip…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.4 MEDIUM
CVE-2026-5306 — Check & Log Email < 2.0.13 - Unauthenticated Stored XSS

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting …

check_\&_log_email | Remote | Cross-Site Scripting
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.6 HIGH
CVE-2026-40967 — Spring AI Unvalidated Filter Expression Converter Vulnerability (Code Injection)

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are no…

spring_ai | Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.9 MEDIUM
CVE-2026-40356 — Kerberos 5 Integer Underflow Out-of-Bounds Read Vulnerability

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registe…

kerberos_5 | Remote | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7228 — SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the a…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7227 — SourceCodester Pizzafy Ecommerce System ajax.php login sql injection

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results i…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7226 — SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the ar…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7225 — SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu. Executing a manipula…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7224 — SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of …

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.4 MEDIUM
CVE-2026-6809 — Social Post Embed <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sa…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
Showing 20 of 5842 Results