Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-56705 — Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFi…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.1 MEDIUM
CVE-2026-56704 — Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafte…

Remote | Cross-Site Scripting
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.2 HIGH
CVE-2026-56703 — Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM I…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.8 HIGH
CVE-2026-56702 — Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default …

Remote | Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.1 HIGH
CVE-2026-34968 — Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker …

Remote | Path Traversal
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
5.4 MEDIUM
CVE-2026-34967 — Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path tr…

Remote | Path Traversal
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
5.8 MEDIUM
CVE-2026-34964 — Adminer before 5.5.0 SSRF via PDO DSN Injection

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non…

Remote | Server-Side Request Forgery
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.7 MEDIUM
CVE-2026-34959 — Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply …

Remote | Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.3 MEDIUM
CVE-2026-19801 — BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Sho…

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This i…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
2.3 LOW
CVE-2026-16434 — Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefi…

Remote | Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-15023 — Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Param…

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.3 MEDIUM
CVE-2026-10630 — WP Courses LMS <= 3.2.29 - Insecure Direct Object Reference to Authenticated (Custom+) Se…

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.5 HIGH
CVE-2026-66766 — Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection)

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input t…

Remote | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
5.5 MEDIUM
CVE-2026-59183 — OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Deco…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 throu…

| Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.2 MEDIUM
CVE-2026-55373 — OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample cou…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop v…

openexr | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.9 MEDIUM
CVE-2026-55371 — OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL po…

openexr | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.1 MEDIUM
CVE-2026-55059 — OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulner…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bound…

openexr | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NONE
CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil i…

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the …

openexr | Remote | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.1 HIGH
CVE-2026-53532 — OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file c…

openexr | Remote | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.7 MEDIUM
CVE-2026-78435 — Faveo Helpdesk Logo SettingsController.php unlink path traversal

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Suc…

helpdesk | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11534 Results