Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-90597 — itsourcecode Sales and Inventory System sup_edit1.php sql injection

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argum…

sales_and_inventory_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90596 — embedded-graphics image_raw.rs new/bytes_per_row integer overflow

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer ov…

Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.9 LOW
CVE-2026-52297 — FFmpeg MOV Parsing Out-of-Bounds Read

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.9 LOW
CVE-2026-52296 — FFmpeg WMA Out-of-Bounds Read

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.1 LOW
CVE-2026-35867 — LB-LINK AC1900_AZ2 Command Injection Vulnerability

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed…

ac1900_firmware | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90595 — wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo author…

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/Onlin…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90594 — wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java PermissionService…

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.j…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90593 — embedded-graphics image_raw.rs draw_sub_image integer overflow

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width …

Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90584 — TooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin …

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentati…

Remote | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-89050 — Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via …

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing user…

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-88802 — MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanentl…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-88793 — YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escap…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-85129 — Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the ac…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
10.0 CRITICAL
CVE-2026-81648 — CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Setting…

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, …

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-74933 — GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthentic…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.9 LOW
CVE-2026-38332 — TinyEXIF Heap-Based Buffer Over-Read

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.1 HIGH
CVE-2026-37008 — CrewAI Sandbox Bypass via Python Runtime Manipulation

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not a…

| Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.8 MEDIUM
CVE-2026-36989 — LuxSoft LuxCal SQL Injection Vulnerability

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

luxcal_web_calendar | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.4 HIGH
CVE-2026-36453 — Rhymix Insecure Direct Object Reference Vulnerability

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-90583 — kagisearch smallweb Query String Rendering sw.py index cross site scripting

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query Stri…

Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13148 Results