Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-27365 — WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-66589 — WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a through 5.2.30.

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.5 MEDIUM
CVE-2026-73974 — linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across su…

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Pr…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.5 MEDIUM
CVE-2026-73973 — Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename …

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and open…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-66603 — WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-66602 — WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forge…

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a …

Remote | Cross-Site Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-62377 — libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF…

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequenc…

Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-62292 — libheif: Out-of-bounds read in uncompressed unci tile range slicing

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that dec…

Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.3 MEDIUM
CVE-2026-62291 — libheif: Heap out of bounds write in libheif uncompressed encoder when writing images wit…

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled …

| Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-62289 — libheif: Integer underflow in Fraction constructor via double clap transform application

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corru…

Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-53959 — 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authen…

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrie…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.6 HIGH
CVE-2026-53958 — 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEm…

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.3 HIGH
CVE-2026-52877 — Streambert : Insecure Protocol Execution in open-external IPC Handler

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url …

Remote | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-52876 — Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled …

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.4 HIGH
CVE-2026-52875 — Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a ren…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-52873 — Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electr…

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:w…

Remote | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-52872 — Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IP…

| Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.6 HIGH
CVE-2026-52854 — mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser funct…

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts atta…

mediawiki | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-50191 — 4gaBoards: Pre-Account Takeover via SSO Email Linkage

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEn…

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-50186 — 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 12279 Results