Live feed

CVE Feed

Last 30 days — 14,557 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-66623
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

29d ago
CVE-2026-66610
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

29d ago
CVE-2026-66599
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

29d ago
CVE-2026-66587
CRITICAL· 9.8

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

29d ago
CVE-2026-66585
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

29d ago
CVE-2026-66584
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

29d ago
CVE-2026-32558
CRITICAL· 9.8

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

29d ago
CVE-2026-32551
CRITICAL· 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.

29d ago
CVE-2026-32478
HIGH· 8.5

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

29d ago
CVE-2026-32477
HIGH· 8.6

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

29d ago
CVE-2026-32476
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

29d ago
CVE-2026-32471
HIGH· 8.5

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

29d ago
CVE-2026-28190
HIGH· 7.1

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

29d ago
CVE-2026-28171
HIGH· 8.6

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

29d ago
CVE-2026-28167
HIGH· 7.5

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

29d ago
CVE-2026-28166
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

29d ago
CVE-2026-28165
CRITICAL· 9.8

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

29d ago
CVE-2026-28162
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

29d ago
CVE-2026-28153
HIGH· 7.5

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

29d ago
CVE-2026-28152
HIGH· 8.1

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

29d ago
CVE-2026-28151
HIGH· 8.1

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

29d ago
CVE-2025-63080
NONE

Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

29d ago
CVE-2026-78337
NONE

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.

29d ago
CVE-2026-78245
HIGH· 7.3

A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.

29d ago
CVE-2026-78244
HIGH· 7.3

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

29d ago
CVE-2026-76172
HIGH· 7.5

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.

openjsf
29d ago
CVE-2026-59295
MEDIUM· 5.9

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer 1.14.0 - 1.14.16 Micrometer 1.9.18 and earlier

29d ago
CVE-2026-10618
MEDIUM· 5.4

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name.

29d ago
CVE-2026-10582
HIGH· 7.4

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out.

29d ago
CVE-2026-78317
HIGH· 8.8

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

29d ago
CVE-2026-78316
HIGH· 8.8

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

29d ago
CVE-2026-78315
HIGH· 8.8

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

29d ago
CVE-2026-78314
HIGH· 8.8

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

29d ago
CVE-2026-75975
HIGH· 7.5

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.

openjsf
29d ago
CVE-2026-75931
HIGH· 7.5

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.

openjsf
29d ago
CVE-2026-75899
HIGH· 7.5

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version.

openjsf
29d ago
CVE-2026-66897
CRITICAL· 9.9

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.

canonical
29d ago
CVE-2026-16249
NONE

Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.

29d ago
CVE-2026-78321
NONE

The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

29d ago
CVE-2026-78306
NONE

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000