Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-66634 — WordPress Modal Survey plugin <= 2.0.2.2.3 - Insecure Direct Object References (IDOR) vul…

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

Remote | Authorization
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-66633 — WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulne…

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-66629 — WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-66627 — WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

Remote | Misconfiguration
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-66622 — WordPress Depicter Slider plugin <= 4.8.0 - SQL Injection vulnerability

Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

depicter_slider | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-66621 — WordPress Ultimate Dashboard Pro plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard P…

ultimate_dashboard | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
7.2 HIGH
CVE-2026-66620 — WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

optiontree | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-66046 — Expat Denial of Service via storeAtts() Quadratic Complexity

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-n…

libexpat | Remote | Denial of Service
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
8.8 HIGH
CVE-2026-63639 — Valkey: UAF in stream deserialization may lead to remote code execution

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK …

valkey | Remote | Memory Corruption
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
3.3 LOW
CVE-2026-63632 — ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Sh…

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in G…

onnx | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-61407 — Dell Watchdog Timer Driver Exposed IOCTL Privilege Escalation

Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit thi…

| Authorization
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-59949 — yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (Streamin…

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInsta…

Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.8 CRITICAL
CVE-2026-59940 — Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled…

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes…

seroval | Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.4 HIGH
CVE-2026-59825 — Mastodon: Unwanted deactivation of SSL/TLS certificate verification

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL…

mastodon | Remote | Authentication
Aug 18, 2026 Sep 16, 2026
Aug 18, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-56684 — Valkey: TLS pending-data processing use-after-free may allow remote code execution

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger C…

valkey | Remote | Race Condition
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-50187 — Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env files

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory…

oh_my_zsh | Remote | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.9 MEDIUM
CVE-2026-50139 — goshs: Share-link ?token=… redemption races past download limit

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock …

goshs | Remote | Race Condition
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-50138 — goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` ar…

goshs | Remote | Authorization
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-48798 — SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled S…

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote S…

ssh.net | Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.3 HIGH
CVE-2026-45733 — Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron des…

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon…

trilium | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 14714 Results