Live feed

CVE Feed

Last 30 days — 14,751 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-16567
MEDIUM· 5.3

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

29d ago
CVE-2026-13416
LOW· 3.5

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

29d ago
CVE-2026-13415
HIGH· 7.2

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

29d ago
CVE-2026-13414
MEDIUM· 4.8

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

29d ago
CVE-2023-27508
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-27503
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-23544
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22446
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22445
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22437
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22434
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22433
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22430
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22426
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22423
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22420
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22364
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22352
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22343
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22328
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22289
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2026-81491
HIGH· 7.3

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

29d ago
CVE-2026-16895
NONE

A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.

29d ago
CVE-2026-81486
MEDIUM· 5.3

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

29d ago
CVE-2026-81485
MEDIUM· 5.3

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

29d ago
CVE-2026-19398
NONE

An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.

29d ago
CVE-2026-81421
HIGH· 7.3

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

29d ago
CVE-2026-80183
NONE

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.

29d ago
CVE-2026-47874
MEDIUM· 5.3

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

pivotal
29d ago
CVE-2026-47863
MEDIUM· 5.9

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier

broadcom
29d ago
CVE-2026-47862
MEDIUM· 5.4

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

vmware
29d ago
CVE-2026-47861
MEDIUM· 6.3

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

vmware
29d ago
CVE-2026-47860
MEDIUM· 6.5

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

vmware
29d ago
CVE-2026-47859
MEDIUM· 5.4

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

vmware
29d ago
CVE-2026-47857
MEDIUM· 5.9

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

broadcom
29d ago
CVE-2026-47856
MEDIUM· 6.3

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

vmware
29d ago
CVE-2026-47852
HIGH· 7.5

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

vmware
29d ago
CVE-2026-47851
HIGH· 7.5

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

vmware
29d ago
CVE-2026-47850
MEDIUM· 4.3

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

vmware
29d ago
CVE-2026-47845
MEDIUM· 5.3

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

broadcom
29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000