Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-14287 — TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass

The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before ren…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14196 — WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update v…

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanentl…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-13175 — Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR

The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or de…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-13174 — Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other u…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-13173 — Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation

The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-13169 — Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Take…

The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contrib…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-12983 — Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler als…

| Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-11565 — Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load…

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-70408 — acmailer Improper Authorization Vulnerability

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.1 MEDIUM
CVE-2026-66358 — acmailer Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-49419 — Jail reference count underflow

When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup fai…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-49418 — Use-after-free in device pager page list

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page faul…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-49415 — Local privilege escalation via execve(2) TOCTOU race

During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target…

| Race Condition
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-19942 — Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file'…

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio…

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-76050 — SourceCodester Simple Online Food Ordering System ajax.php delete_menu sql injection

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument I…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-76049 — SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injection

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argumen…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-76048 — SourceCodester Simple Online Food Ordering System ajax.php login sql injection

A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the a…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
3.3 LOW
CVE-2026-76014 — BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the a…

| Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
10.0 CRITICAL
CVE-2026-76008 — Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argumen…

cf-n1-s | Remote | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.9 CRITICAL
CVE-2026-76004 — UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the compone…

hiper_1250gw | Remote | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12347 Results