Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-90539 — WWBN AVideo Missing Authentication via menuItems.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attac…

avideo | Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90538 — WWBN AVideo Missing Authorization via playlistsFromUser.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private …

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-90537 — WWBN AVideo Scheduler sendEmail Missing Authorization via Token

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to acce…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90536 — WWBN AVideo Missing Authorization via adsInfo API Endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owne…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.3 MEDIUM
CVE-2026-90535 — Flowise before 3.1.4 Denial of Service via text-to-speech/abort

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownershi…

flowise | Remote | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.1 MEDIUM
CVE-2026-90534 — Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method

Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission che…

flowise | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.0 MEDIUM
CVE-2026-90533 — Flowise before 3.1.4 Broken Access Control via organizationuser

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user re…

flowise | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-15451 — MemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privilege Escalati…

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.4 MEDIUM
CVE-2026-10148 — Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contribut…

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to…

Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.6 HIGH
CVE-2026-90474 — MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional…

mcphub | Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90473 — msgpack-java through 0.9.12 Integer Overflow via MAP32

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element …

messagepack | Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90472 — msgpack-java through 0.9.12 Stack Overflow via Nested Arrays

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft pa…

messagepack | Remote | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.6 MEDIUM
CVE-2026-89172 — Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms

Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.…

| Information Disclosure
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.5 HIGH
CVE-2026-85200 — GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possib…

geo_my_wordpress | Remote | Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.5 MEDIUM
CVE-2026-85198 — MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path

The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to in…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-78175 — Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Exec…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter o…

tutor_lms | Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-78159 — The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution v…

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation o…

the_events_calendar | Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-78006 — The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execu…

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient …

the_events_calendar | Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.5 MEDIUM
CVE-2026-77161 — Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Inj…

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping …

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-17585 — Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure v…

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wp…

royal_elementor_addons | Remote | Information Disclosure
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
Showing 20 of 13182 Results