Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-5049 — Brocade SANnav Path Traversal Vulnerability

A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended direct…

brocade_sannav sannav | Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-5048 — Brocade SANnav SQL Injection Vulnerability

In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of th…

brocade_sannav sannav | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.2 HIGH
CVE-2026-5047 — Brocade SANnav Sensitive Information Disclosure

A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the …

brocade_sannav sannav | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-107459 — Openfind|SecuShare Pro - OS Command Injection

The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105260 — Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF

The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attack…

| Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105198 — LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR

The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary,…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105197 — LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR

The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated us…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105196 — LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API

The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoin…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105195 — Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor ro…

booking_calendar | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105194 — Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Do…

The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order…

easy_digital_downloads | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105193 — Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification…

The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthen…

booking_calendar | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-104646 — Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Short…

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing the…

image_photo_gallery_final_tiles_grid | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-104645 — Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, I…

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a dif…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-103692 — Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Fun…

The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-103646 — Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' P…

The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitte…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-103309 — GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage

The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated use…

| Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-94587 — Brocade Fabric OS WebTools Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 thro…

fabric_operating_system fabric_os | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-94586 — Brocade Fabric OS Command Injection Vulnerability

A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 th…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.7 HIGH
CVE-2026-94585 — Brocade Fabric OS Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-94581 — Brocade Fabric OS OS Command Injection Vulnerability

An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allows an authenticated, high-privileged remo…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15559 Results