Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-15680 — Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution…

Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected ins…

| Injection
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15598 — antv layout object.js setNestedValue prototype pollution

A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly c…

layout | Remote | Misconfiguration
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
7.5 HIGH
CVE-2026-15597 — SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argum…

class_and_exam_timetabling_system | Remote | Injection
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
5.0 MEDIUM
CVE-2026-15596 — SourceCodester Class and Exam Timetabling System subject.php cross site scripting

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
7.1 HIGH
CVE-2026-58410 — ChurchCRM: Improper object-level authorization allows low-privileged users to read and mo…

ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify othe…

churchcrm | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
9.1 CRITICAL
CVE-2026-58409 — ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP…

churchcrm | Remote | Authentication
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.2 HIGH
CVE-2026-48364 — ColdFusion | Uncontrolled Search Path Element (CWE-427)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exp…

coldfusion | Path Traversal
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.2 HIGH
CVE-2026-48363 — ColdFusion | Uncontrolled Search Path Element (CWE-427)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exp…

coldfusion | Path Traversal
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
5.0 MEDIUM
CVE-2026-15595 — SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subj…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
3.7 LOW
CVE-2026-15594 — waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization

A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation o…

waoowaoo | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
6.5 MEDIUM
CVE-2026-58408 — ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to E…

ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. The POST /CSVCreateFile…

churchcrm | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.8 HIGH
CVE-2026-55773 — CedarJava has a policy injection vulnerability

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, …

Remote | Injection
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.8 HIGH
CVE-2026-55771 — CedarJava has policy injection, type confusion, and incorrect equality comparison vulnera…

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted nul…

Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
6.4 MEDIUM
CVE-2026-12536 — Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mo…

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5 due to insufficient input sa…

avada_builder | Remote | Cross-Site Scripting
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
4.3 MEDIUM
CVE-2026-12385 — Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensit…

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenti…

smart_slider_3 | Remote | Information Disclosure
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
9.5 CRITICAL
CVE-2026-6875 — Sandbox Escape in ServiceNow AI Platform

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to…

Remote | Injection
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
5.1 MEDIUM
CVE-2026-58228 — Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>

Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView…

phoenix_live_view | Remote | Cross-Site Scripting
Jul 13, 2026 Jul 13, 2026
Jul 13, 2026
Jul 13, 2026
8.8 HIGH
CVE-2026-55772 — CedarJava has a type confusion vulnerability

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, …

Remote | Authorization
Jul 13, 2026 Jul 21, 2026
Jul 13, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-49972 — Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised …

Remote | Misconfiguration
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
6.1 MEDIUM
CVE-2026-49971 — Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload

Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files cont…

Remote | Cross-Site Scripting
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
Showing 20 of 10953 Results