Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2026-67103 — HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabli…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.1 HIGH
CVE-2026-67102 — HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and fun…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.8 CRITICAL
CVE-2026-67100 — HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extra…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-75157 — Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDI…

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that D…

airflow | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.3 CRITICAL
CVE-2026-67101 — HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requ…

Remote | Server-Side Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.8 HIGH
CVE-2026-12384 — Broken Access Control in TECHIN2B Application

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. N…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-85705 — Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and 'longitude'…

The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient es…

location_manager | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-92249 — Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting via 's' Parame…

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitizatio…

qi_addons_for_elementor | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-15275 — WP Multi Store Locator Pro <= 4.5.1 - Unauthenticated SQL Injection via 'store_locator_se…

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insuffic…

| Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-12739 — WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Pos…

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not pr…

| Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-85652 — Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' S…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.…

| Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-16777 — Store Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File …

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filen…

| Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-15004 — FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Autho…

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to i…

| Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-12954 — Mapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'ac…

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function pe…

| Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-14472 — Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input san…

| Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-14323 — Printcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitr…

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This mak…

| Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-75961 — NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of t…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due t…

| Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-92622 — Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient inpu…

strong_testimonials | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-90981 — Newsletter <= 9.3.8 - Reflected Cross-Site Scripting via 'nn' Parameter

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insu…

| Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-13471 — LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrar…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePoin…

| Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14461 Results