Live feed

CVE Feed

Last 30 days — 14,643 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-66604
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.

29d ago
CVE-2026-66601
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

29d ago
CVE-2026-66600
CRITICAL· 9.1

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

29d ago
CVE-2026-66598
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

29d ago
CVE-2026-66597
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.

29d ago
CVE-2026-66595
MEDIUM· 5.9

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

29d ago
CVE-2026-66594
HIGH· 8.5

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

29d ago
CVE-2026-66593
CRITICAL· 9.3

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

29d ago
CVE-2026-66592
CRITICAL· 9.3

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

29d ago
CVE-2026-66590
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.

29d ago
CVE-2026-66586
MEDIUM· 6.6

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

29d ago
CVE-2026-66583
CRITICAL· 9.8

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

29d ago
CVE-2026-66582
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

29d ago
CVE-2026-66581
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

29d ago
CVE-2026-28150
HIGH· 8.1

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

29d ago
CVE-2025-62307
MEDIUM· 5.4

HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

29d ago
CVE-2025-53999
MEDIUM· 6.5

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

29d ago
CVE-2025-15689
CRITICAL· 9.8

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

29d ago
CVE-2025-15688
CRITICAL· 9.3

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

29d ago
CVE-2025-15637
HIGH· 8.1

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

29d ago
CVE-2026-77067
MEDIUM· 5.0

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API.

29d ago
CVE-2026-77066
MEDIUM· 5.0

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and createPageSaveRequest applies the same check, so the omission is specific to this resolver. An authenticated user can direct the server to request arbitrary internal endpoints. The response is parsed as a feed or as HTML and the resolver returns the resulting url, title, description and type fields, so disclosure is limited to feed-shaped metadata and to link elements advertising RSS or Atom feeds; requests that do not parse still distinguish reachable ports from unreachable ones through the resulting error.

29d ago
CVE-2026-77026
NONE

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

29d ago
CVE-2026-73199
MEDIUM· 6.5

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.

29d ago
CVE-2026-73198
HIGH· 7.5

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.

redhatfreeipa
29d ago
CVE-2026-73197
HIGH· 7.5

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.

redhatfreeipa
29d ago
CVE-2026-73196
MEDIUM· 4.3

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.

redhatfreeipa
29d ago
CVE-2026-13097
HIGH· 8.7

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

redhatfreeipa
29d ago
CVE-2026-11861
CRITICAL· 9.6

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

freeiparedhat
29d ago
CVE-2026-18917
HIGH· 7.8

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

29d ago
CVE-2026-77014
MEDIUM· 5.3

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

29d ago
CVE-2026-76610
NONE

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

29d ago
CVE-2026-14953
MEDIUM· 4.3

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

29d ago
CVE-2026-14952
HIGH· 7.5

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

29d ago
CVE-2026-14951
HIGH· 8.0

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

29d ago
CVE-2026-14950
CRITICAL· 9.8

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

29d ago
CVE-2026-14949
MEDIUM· 6.5

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

29d ago
CVE-2026-14948
HIGH· 8.8

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

29d ago
CVE-2026-14947
HIGH· 7.2

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

29d ago
CVE-2026-14946
HIGH· 7.2

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000