Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-91794 — Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vuln…

An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data,…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-91793 — Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reco…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-91792 — Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the applicati…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-91791 — Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the applic…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-91790 — Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-fre…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-91789 — Foxit PDF Editor/Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerabi…

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly…

pdf_editor pdf_reader | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.7 MEDIUM
CVE-2026-91788 — Foxit PDF Editor/Reader Missing Authorization Information Disclosure Vulnerability

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potent…

pdf_editor pdf_reader | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.1 MEDIUM
CVE-2026-50228 — Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium …

nitrosense | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.1 MEDIUM
CVE-2026-50227 — MQTT WebSocket Command Execution Vulnerability in NitroSense

An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to i…

nitrosense | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-82331 — Apache BuildStream: tar source extraction escape

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files …

| Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-6831 — Advanced Contact form 7 DB <= 2.1.1 - Missing Authorization to Authenticated (Contributor…

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.4 MEDIUM
CVE-2026-5924 — Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Map…

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This i…

getwid | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.7 LOW
CVE-2026-93528 — NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quo…

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's …

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-93511 — Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass

The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge pa…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.3 MEDIUM
CVE-2026-93510 — Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Bal…

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, S…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.1 HIGH
CVE-2026-93508 — WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to crea…

wc_fields_factory | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.3 LOW
CVE-2026-93507 — WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disc…

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitr…

wc_fields_factory | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
2.7 LOW
CVE-2026-91077 — Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disc…

The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level …

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.8 MEDIUM
CVE-2026-91073 — Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.3 MEDIUM
CVE-2026-91025 — Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's o…

booking_manager | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14274 Results