Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 HIGH
CVE-2026-7823 — Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-7822 — itsourcecode Courier Management System print_pdets.php sql injection

A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The manipulation of the argument ids leads to sql injectio…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-7812 — 54yyyu code-mcp MCP Tool server.py git_operation command injection

A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the function git_operation of the file src/code_mcp/server.py of the component MCP…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-7811 — 54yyyu code-mcp MCP File server.py is_safe_path path traversal

A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path of the file src/code_mcp/server.py of the component…

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-4362 — ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget C…

The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to…

Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-7810 — UsamaK98 python-notebook-mcp server.py add_cell path traversal

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. …

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-5957 — EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-temp…

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of …

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
9.8 CRITICAL
CVE-2026-5294 — GeekyBot <= 1.2.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Installatio…

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispa…

Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-5159 — Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site S…

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, …

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.2 HIGH
CVE-2026-4803 — Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via …

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and inclu…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-4665 — WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions up to, and including, 2.7.10. This is due to the …

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-3456 — GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.2.0 - Una…

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.7 HIGH
CVE-2026-35228 — Oracle Open Source Projects Oracle MCP Server Helper Tool SQL Injection Vulnerability

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulner…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-2948 — Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (C…

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() fun…

Remote | Server-Side Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6704 — Blog Settings <= 1.0 - Reflected Cross-Site Scripting via 'page' Parameter

The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0. This is due to insufficient input sanitizati…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6702 — Publish 2 Ping.fm <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via …

The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the '/wp-admi…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-6701 — addfreespace <= 0.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Set…

The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.3. This is due to missing or incorrect nonce validation on a function. This…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-6700 — DX Sources <= 2.0.1 - Cross-Site Request Forgery to Settings Update

The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the settings_page_…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6696 — Zingaya Click-to-Call <= 1.0 - Reflected Cross-Site Scripting via 'email' Parameter

The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_name', 'last_name', and 'phone' parameters on the plugin's sign-up admin page in…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-6255 — Simple Owl Shortcodes <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode in all versions up to, and including, 2.1.1 due to …

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
Showing 20 of 5628 Results