Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.3 LOW
CVE-2026-2994 — Concrete CMS below 9.4.8 is vulnerable to CSRF by a Rogue Admin using the Anti-Spam Allow…

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter which can leads to a security bypass since change…

concrete_cms | Remote | Cross-Site Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.9 HIGH
CVE-2026-3452 — Concrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Ex…

Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can …

concrete_cms | Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.8 MEDIUM
CVE-2026-3244 — Concrete CMS below version 9.4.8 is vulnerable to Stored XSS in Search Results via Page N…

In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where page names and content are rendered without proper HTML encoding in search resu…

concrete_cms | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-2292 — Morkva UA Shipping <= 1.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting …

The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and outp…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.4 MEDIUM
CVE-2026-2289 — Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Bl…

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output esca…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-1980 — WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Expo…

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This…

wpbookit | Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1945 — WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and '…

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient …

wpbookit | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2026-1651 — Email Subscribers & Newsletters <= 5.9.16 - Authenticated (Administrator+) SQL Injection …

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping…

Remote | Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.2 HIGH
CVE-2026-1273 — PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API …

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/…

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.3 HIGH
CVE-2026-3266 — Improper access control vulnerability has been discovered in OpenText™ Filr.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. …

filr | Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
10.0 CRITICAL
CVE-2026-28289 — FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with …

freescout | Remote | Misconfiguration
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.4 HIGH
CVE-2026-27981 — HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.2 CRITICAL
CVE-2026-27971 — Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user…

qwik | Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.5 HIGH
CVE-2026-27932 — joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows…

Remote | Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.6 HIGH
CVE-2026-27905 — BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path i…

bentoml | Path Traversal
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.4 HIGH
CVE-2026-27622 — OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals…

openexr | Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.2 HIGH
CVE-2026-27601 — Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an …

Remote | Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.0 MEDIUM
CVE-2026-27600 — HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST req…

Remote | Server-Side Request Forgery
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.1 CRITICAL
CVE-2026-26279 — Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injec…

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields de…

froxlor | Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
4.6 MEDIUM
CVE-2026-26272 — HomeBox affected by Stored XSS via HTML/SVG Attachment Upload

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does n…

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
Showing 20 of 4949 Results