Live feed

CVE Feed

Last 30 days — 14,766 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-81579
HIGH· 8.8

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

29d ago
CVE-2026-81576
HIGH· 7.7

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

29d ago
CVE-2026-81575
HIGH· 7.5

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

29d ago
CVE-2026-81574
HIGH· 8.2

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.

29d ago
CVE-2026-81573
HIGH· 8.6

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

29d ago
CVE-2026-81572
HIGH· 7.8

In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.

29d ago
CVE-2026-81279
MEDIUM· 5.4

Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

29d ago
CVE-2026-81277
HIGH· 8.5

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

29d ago
CVE-2026-81276
MEDIUM· 5.3

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

29d ago
CVE-2026-81274
MEDIUM· 5.3

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

29d ago
CVE-2026-81273
HIGH· 8.1

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

29d ago
CVE-2026-81272
MEDIUM· 4.9

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

29d ago
CVE-2026-81271
HIGH· 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

29d ago
CVE-2026-80433
HIGH· 7.5

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

29d ago
CVE-2026-78293
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

29d ago
CVE-2026-78292
CRITICAL· 9.8

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

29d ago
CVE-2026-78289
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

29d ago
CVE-2026-78288
CRITICAL· 9.3

Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

29d ago
CVE-2026-78286
CRITICAL· 9.8

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

29d ago
CVE-2026-78285
HIGH· 8.5

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

29d ago
CVE-2026-78283
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

29d ago
CVE-2026-78281
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

29d ago
CVE-2026-78276
HIGH· 7.2

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

29d ago
CVE-2026-78275
MEDIUM· 6.8

Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

29d ago
CVE-2026-78274
CRITICAL· 9.1

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

29d ago
CVE-2026-78273
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

29d ago
CVE-2026-78271
HIGH· 7.2

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

29d ago
CVE-2026-78261
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

29d ago
CVE-2026-78260
CRITICAL· 9.3

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

29d ago
CVE-2026-78257
HIGH· 8.8

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

29d ago
CVE-2026-75020
HIGH· 8.1

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

apache
29d ago
CVE-2026-75005
HIGH· 7.5

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

apache
29d ago
CVE-2026-74848
HIGH· 7.5

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

apache
29d ago
CVE-2026-59355
MEDIUM· 6.1

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.

broadcom
29d ago
CVE-2026-59354
CRITICAL· 9.6

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

vmware
29d ago
CVE-2026-32566
CRITICAL· 9.8

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

29d ago
CVE-2026-32564
HIGH· 8.5

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

29d ago
CVE-2026-32550
HIGH· 8.5

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

29d ago
CVE-2026-32479
CRITICAL· 9.3

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

29d ago
CVE-2026-27330
HIGH· 8.6

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000