Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2026-82685 — Confirmation token accepted on any record in AshAuthentication

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take ov…

ash_authentication | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-81829 — Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via un…

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, th…

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
2.3 LOW
CVE-2026-81637 — Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attack…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.2 HIGH
CVE-2026-81632 — Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use s…

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-81453 — Dell OpenManage Server Administrator Path Traversal Vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker w…

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.4 MEDIUM
CVE-2026-81443 — Dell OpenManage Server Administrator Server-Side Request Forgery Vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit t…

Remote | Server-Side Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.1 HIGH
CVE-2026-81442 — Dell OpenManage Server Administrator Improper Privilege Management Vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this …

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.4 MEDIUM
CVE-2026-80355 — Dell OpenManage Server Administrator Cross-Site Request Forgery Vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit …

Remote | Cross-Site Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.6 HIGH
CVE-2026-80218 — Sign-in token minted for one resource accepted by another in AshAuthentication

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. A…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-78528 — WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-78295 — WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

Remote | Cross-Site Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-78294 — WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-78223 — Token revocation record built from unverified JWT claims in AshAuthentication

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-74017 — WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

user_registration | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.4 MEDIUM
CVE-2026-74005 — WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnera…

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

Remote | Cross-Site Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-74002 — WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-74000 — WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerability

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.4 MEDIUM
CVE-2026-73999 — WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) vulnerability

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-71568 — BMCtest exposes Ironic without authentication and TLS during the test

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and si…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-66676 — WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14768 Results