Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-94001 — Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-passw…

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained r…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.6 MEDIUM
CVE-2026-94000 — Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to r…

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a gro…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.2 MEDIUM
CVE-2026-93999 — Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled…

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores re…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.6 MEDIUM
CVE-2026-93987 — rclone serve docker Path Traversal via Volume Name

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as fi…

| Path Traversal
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
3.1 LOW
CVE-2026-93986 — rclone before 1.75.1 Path Traversal via Directory Listing Names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names…

Remote | Path Traversal
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
9.9 CRITICAL
CVE-2026-93985 — OpenPanel js-runtime JavaScript Template Sandbox Escape RCE

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Att…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.9 MEDIUM
CVE-2026-93984 — OpenPanel API Authentication Bypass via Unverified Client Secret

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with onl…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-93983 — OpenPanel SQL Injection via ClickHouse Property Key Filter

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypas…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.8 MEDIUM
CVE-2026-93982 — OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application s…

| Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.7 MEDIUM
CVE-2026-93981 — hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single chil…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-78030 — DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and db…

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require with…

| Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-9858 — Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscri…

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_ord…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-9766 — Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arb…

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is autho…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-9613 — Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscri…

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifyin…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-9289 — WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API …

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is d…

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
9.9 CRITICAL
CVE-2026-93742 — Totolink A3002MU formWsc command injection

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes com…

a3002mu | Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-8354 — Gum Addon for Elementor <= 1.3.15 - Authenticated (Contributor+) Stored Cross-Site Script…

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input saniti…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.7 MEDIUM
CVE-2026-76579 — LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and o…

litespeed_cache | Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-5410 — Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting via S…

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-1256 — YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authentic…

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capabi…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 14195 Results