Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-81295 — WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-81292 — WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-81282 — WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scrip…

Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-81281 — WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84849 — WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85239 — MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service

A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTe…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.6 HIGH
CVE-2026-85238 — Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking

MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authentic…

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-85237 — Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did no…

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-85236 — MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. …

Remote | Cross-Site Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85138 — SeaCMS WeChat index.php addslashes sql injection

A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85137 — SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection

A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.1 MEDIUM
CVE-2026-84967 — Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell …

A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-84966 — BSON element injection via NUL-embedded document keys in builder append

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremel…

c_driver | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-84965 — Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale point…

c_driver | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.2 HIGH
CVE-2026-84964 — Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS cl…

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially fo…

c_driver | Remote | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.3 MEDIUM
CVE-2026-84963 — Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON…

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be…

c_driver | Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.7 MEDIUM
CVE-2026-84962 — Authenticated KMS request forgery via CRLF injection in GCP key identifier strings

An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-l…

libmongocrypt | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-83961 — ColdFusion | Improper Authentication (CWE-287)

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The …

| Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.8 MEDIUM
CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external enti…

| XML External Entity
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user w…

Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12661 Results