Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.0 MEDIUM
CVE-2026-82488 — Beetel 450TC3 User Management cross site scripting

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site sc…

450tc3 | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82487 — Beetel 450TC3 password recovery

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploi…

450tc3 | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
5.1 MEDIUM
CVE-2026-82486 — SiteServer SSCMS Agent Installation Workflow access control

A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument Secur…

sscms | Remote | Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82485 — itsourcecode Sales and Inventory System pro_edit.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the arg…

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-82484 — itsourcecode Sales and Inventory System emp_searchfrm.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. …

sales_and_inventory_system | Remote | Injection
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82483 — coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cro…

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The …

coppermine_photo_gallery | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
4.0 MEDIUM
CVE-2026-82482 — coppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site …

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint…

coppermine_photo_gallery | Remote | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-81766 — Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation v…

The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-su…

| Authorization
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-81660 — Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and output…

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-78364 — MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low …

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-76585 — Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Par…

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated …

customer_reviews_for_woocommerce | Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-19722 — WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users …

| Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-14835 — SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Po…

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restric…

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
0.0 NA
CVE-2026-14307 — Geotargeting WP < 3.5.6.2 - Reflected XSS

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing una…

| Cross-Site Scripting
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.4 HIGH
CVE-2026-82480 — NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cF…

cfs | Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
6.3 MEDIUM
CVE-2026-82479 — NASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflow

A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of th…

cfs | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-82478 — NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServe…

trick | Remote | Memory Corruption
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
9.8 CRITICAL
CVE-2026-15980 — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and impro…

Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
2.1 LOW
CVE-2026-77846 — JSON path injection via unescaped get_path segments in AshSqlite

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the applicati…

ash_sqlite | Path Traversal
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
7.6 HIGH
CVE-2026-75759 — Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying n…

oidcc | Remote | Authentication
Aug 30, 2026 Aug 30, 2026
Aug 30, 2026
Aug 30, 2026
Showing 20 of 11960 Results