Live feed

CVE Feed

Last 30 days — 9,264 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-56027
CRITICAL· 9.9

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

29d ago
CVE-2026-56026
MEDIUM· 6.4

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

29d ago
CVE-2026-56025
HIGH· 7.5

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

29d ago
CVE-2026-56011
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

29d ago
CVE-2026-56010
HIGH· 8.8

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

29d ago
CVE-2026-56008
HIGH· 8.8

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

29d ago
CVE-2026-54847
HIGH· 7.5

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

29d ago
CVE-2026-54846
HIGH· 7.5

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

29d ago
CVE-2026-54840
HIGH· 7.3

Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

29d ago
CVE-2026-54839
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions.

29d ago
CVE-2026-54837
HIGH· 7.5

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

29d ago
CVE-2026-54835
HIGH· 7.5

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

29d ago
CVE-2026-54834
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

29d ago
CVE-2026-54833
HIGH· 7.4

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

29d ago
CVE-2026-54832
HIGH· 7.5

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

29d ago
CVE-2026-54831
CRITICAL· 9.3

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

29d ago
CVE-2026-54827
CRITICAL· 9.3

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

29d ago
CVE-2026-54826
HIGH· 7.6

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

29d ago
CVE-2026-54825
CRITICAL· 9.3

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

29d ago
CVE-2026-54824
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

29d ago
CVE-2026-54820
CRITICAL· 9.3

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

29d ago
CVE-2026-52701
MEDIUM· 6.5

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

29d ago
CVE-2026-4339
MEDIUM· 6.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate data from internal network services via supplying internal URLs as file attachments in post creation requests.. Mattermost Advisory ID: MMSA-2026-00635

mattermost
29d ago
CVE-2026-45257
HIGH· 7.8

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS on the transmit side, the file-backed mbufs reach the receiver's decryption path unchanged. Decrypting a record in place then overwrites the backing file's page cache instead of a private copy of the data. An unprivileged local user who can read a file can overwrite its contents with data of their choosing by sending the file over a loopback connection on which they have enabled KTLS receive. The write modifies the page cache directly, so it bypasses file flags such as schg and is written back to disk. By overwriting a setuid binary or other trusted file, a local user can escalate privileges, potentially gaining full control of the affected system.

freebsd
29d ago
CVE-2026-45256
MEDIUM· 5.5

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the result before delivering the signal. The signal was sent even when the permission check failed. The system call returned the resulting error to the caller, but by then the signal had already been delivered. The missing check allows an unprivileged local user who knows or can guess a target's process and thread IDs to send any signal to a process they would not normally be permitted to signal, including processes owned by other users or by root. The same check enforces jail boundaries, so a jailed process can signal processes on the host or in other jails. Thread IDs are allocated globally and sequentially, and so can be discovered by brute force with no visibility into the target. An attacker can stop or terminate arbitrary processes, including critical system daemons, resulting in a Denial of Service (DoS).

freebsd
29d ago
CVE-2026-3472
LOW· 3.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content rendered by a victim's client.. Mattermost Advisory ID: MMSA-2026-00619

mattermost
29d ago
CVE-2026-30041
HIGH· 7.5

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

29d ago
CVE-2026-30040
MEDIUM· 6.5

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.

29d ago
CVE-2026-24547
MEDIUM· 5.3

Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

29d ago
CVE-2025-68075
MEDIUM· 6.5

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

29d ago
CVE-2025-68074
MEDIUM· 6.5

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

29d ago
CVE-2025-68064
HIGH· 7.5

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

29d ago
CVE-2025-68063
HIGH· 7.5

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

29d ago
CVE-2025-68052
HIGH· 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

29d ago
CVE-2025-66123
MEDIUM· 5.3

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

29d ago
CVE-2025-64637
MEDIUM· 5.3

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

29d ago
CVE-2025-64636
MEDIUM· 5.3

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

29d ago
CVE-2025-63079
MEDIUM· 4.3

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

29d ago
CVE-2025-63078
MEDIUM· 4.3

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

29d ago
CVE-2025-63041
MEDIUM· 5.4

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000