Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.3 LOW
CVE-2026-92106 — lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.3 MEDIUM
CVE-2026-97863 — misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Mod…

The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuratio…

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-92573 — Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompressio…

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authentic…

qpid_broker-j | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-92564 — Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authenticatio…

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are …

qpid_broker-j | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-92560 — Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authe…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. …

qpid_broker-j | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-92550 — Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authe…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. …

qpid_broker-j | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.2 MEDIUM
CVE-2026-88848 — MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restricti…

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with th…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-86837 — Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifie…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-80514 — wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, all…

wpforo_forum | Remote | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6088 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that all…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6087 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that all…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6086 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types'…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6085 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types'…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6084 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/variants' that allow…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6083 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint ' /inventory/configuration/pricing-tiers' that…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-6082 — Stored Cross-Site Scripting in StockAgile by Novadigits technologies

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/payment-methods' tha…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-96752 — Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Neste…

The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all versions up to, and including, 5.7.10 du…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-96568 — Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting…

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficie…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.6 MEDIUM
CVE-2026-96448 — Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privile…

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator …

single_sign-on build_of_keycloak | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-95866 — User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Fi…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to…

profile_builder | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14177 Results