Live feed

CVE Feed

Last 30 days — 15,098 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-14326
LOW· 3.8

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

29d ago
CVE-2026-14255
MEDIUM· 5.5

A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

29d ago
CVE-2026-10821
MEDIUM· 6.6

The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.

29d ago
CVE-2025-9314
CRITICAL· 9.8

The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

29d ago
CVE-2025-8945
MEDIUM· 5.3

The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

29d ago
CVE-2025-15692
LOW· 3.5

The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.

29d ago
CVE-2025-15490
MEDIUM· 5.3

The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

29d ago
CVE-2025-15489
MEDIUM· 5.3

The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

29d ago
CVE-2025-15485
HIGH· 8.2

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

29d ago
CVE-2025-15481
MEDIUM· 5.3

The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.

29d ago
CVE-2025-13398
NONE

Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.

29d ago
CVE-2024-7956
NONE

A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.

29d ago
CVE-2024-3773
MEDIUM· 5.9

The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

29d ago
CVE-2023-3360
LOW· 3.3

The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

29d ago
CVE-2026-81269
MEDIUM· 5.3

Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.

data_field_project
29d ago
CVE-2026-81205
MEDIUM· 5.3

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

miniorange
29d ago
CVE-2026-81201
MEDIUM· 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

monster_menus_project
29d ago
CVE-2026-81168
LOW· 3.7

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

captcha_protected_page_project
29d ago
CVE-2026-81167
MEDIUM· 4.8

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.

address_suggestion_project
29d ago
CVE-2026-81166
MEDIUM· 5.3

Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.

lakedrops
29d ago
CVE-2026-81165
MEDIUM· 5.3

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

blazy_project
29d ago
CVE-2026-81164
MEDIUM· 5.4

Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.

29d ago
CVE-2026-81162
MEDIUM· 5.3

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

dxpr_builder_project
29d ago
CVE-2026-81161
LOW· 3.3

Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.

content_moderation_notifications_project
29d ago
CVE-2026-81160
MEDIUM· 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.

slick_carousel_project
29d ago
CVE-2026-81159
LOW· 3.7

Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.

centarro
29d ago
CVE-2026-81158
MEDIUM· 5.3

Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

entity_api_project
29d ago
CVE-2026-76782
HIGH· 7.3

Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.

29d ago
CVE-2026-76759
HIGH· 7.3

Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.

29d ago
CVE-2026-76758
MEDIUM· 5.9

Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.

29d ago
CVE-2026-76757
MEDIUM· 5.9

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

29d ago
CVE-2026-76756
MEDIUM· 5.9

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

29d ago
CVE-2026-76755
MEDIUM· 5.9

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

29d ago
CVE-2026-73478
MEDIUM· 5.3

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

diff_project
29d ago
CVE-2026-73477
MEDIUM· 5.3

Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.

quick_tabs_project
29d ago
CVE-2026-73476
MEDIUM· 5.4

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

external_authentication_project
29d ago
CVE-2026-73475
CRITICAL· 9.1

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

centarro
29d ago
CVE-2026-73474
MEDIUM· 5.3

Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.

entity_share_websub_project
29d ago
CVE-2026-18986
MEDIUM· 4.8

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.

entity_browser_project
29d ago
CVE-2026-16647
MEDIUM· 4.1

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

zyxware
29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000