Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-22618 — Eaton Intelligent Power Protector Insecure HTTP Response Header Vulnerability

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attack…

Remote | Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.7 MEDIUM
CVE-2026-22617 — Eaton Intelligent Power Protector Cookie Insecure Storage

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. Th…

Remote | Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.3 MEDIUM
CVE-2026-40118 — Arcserve UDP Console Information Disclosure Vulnerability

UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product t…

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.5 MEDIUM
CVE-2026-22616 — Eaton Intelligent Power Protector Web Authentication Brute Force

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been …

Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.0 MEDIUM
CVE-2026-22615 — Eaton Intelligent Power Protector Remote Command Execution Vulnerability

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious cod…

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.3 MEDIUM
CVE-2023-5872 — Wago: Vulnerability in Smart Designer Web-Application

In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.

smart_designer | Remote | Information Disclosure
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.8 HIGH
CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions

In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, i…

Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-5070 — Vantage <= 1.20.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery…

The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the galler…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.1 MEDIUM
CVE-2026-4032 — CodeColorer <= 0.10.1 - Unauthenticated Stored Cross-Site Scripting via 'class' attribute…

The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient inpu…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-3878 — WP Docs <= 2.2.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_op…

The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parameter in all versions up to, and including, 2.2.9 due to insufficient input sanit…

wp_docs | Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.7 HIGH
CVE-2026-6351 — Openfind|MailGates/MailAudit - CRLF Injection

MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.

mailaudit mailgates | Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-6350 — Openfind|MailGates/MailAudit - Stack-based Buffer Overflow

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.

mailaudit mailgates | Remote | Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
10.0 CRITICAL
CVE-2026-6349 — HGiga|iSherlock - OS Command Injection

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.3 CRITICAL
CVE-2026-6348 — Simopro Technology|WinMatrix - Missing Authentication

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machin…

| Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.4 HIGH
CVE-2026-41015 — Radare2 Unix Command Injection Vulnerability

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release…

radare2 | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-3885 — WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored…

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to…

shortcodes_ultimate | Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.4 MEDIUM
CVE-2026-3428 — ASUS Member Center TOC-TOU Privilege Escalation

A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a T…

| Race Condition
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.4 MEDIUM
CVE-2026-1880 — "ASUS DriverHub Privilege Escalation Vulnerability"

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources duri…

driverhub | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.9 MEDIUM
CVE-2026-40962 — FFmpeg CENC Subsample Buffer Overflow Vulnerability

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

ffmpeg | Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
3.3 LOW
CVE-2026-40505 — MuPDF mutool ANSI Injection via Metadata

MuPDF mutool does not sanitize PDF metadata fields before writing them to terminal output, allowing attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata. Attackers can emb…

mupdf | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
Showing 20 of 6555 Results