Live feed

CVE Feed

Last 30 days — 14,974 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-84775
MEDIUM· 5.3

Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.

29d ago
CVE-2026-84772
MEDIUM· 5.5

Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.

29d ago
CVE-2026-84771
MEDIUM· 5.3

Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.

29d ago
CVE-2026-84770
HIGH· 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

29d ago
CVE-2026-84764
HIGH· 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

29d ago
CVE-2026-84760
MEDIUM· 5.3

Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.

29d ago
CVE-2026-84759
HIGH· 7.1

Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.

29d ago
CVE-2026-84217
MEDIUM· 5.4

Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3.

29d ago
CVE-2026-83562
MEDIUM· 6.5

Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.

29d ago
CVE-2026-82223
MEDIUM· 6.5

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.

29d ago
CVE-2026-81775
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.

29d ago
CVE-2026-81774
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.

29d ago
CVE-2026-81772
HIGH· 8.8

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

29d ago
CVE-2026-81771
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.

29d ago
CVE-2026-81770
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.

29d ago
CVE-2026-81769
HIGH· 8.8

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

29d ago
CVE-2026-81294
CRITICAL· 9.8

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

29d ago
CVE-2026-81289
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.

29d ago
CVE-2026-81288
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.

29d ago
CVE-2026-81286
CRITICAL· 9.3

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

29d ago
CVE-2026-81283
HIGH· 8.8

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

29d ago
CVE-2026-66652
MEDIUM· 5.4

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.

29d ago
CVE-2026-82958
NONE

In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing" template as raw, un-escaped strings, and then parses the resulting string as JSON. Because the placeholder engine performs no JSON escaping and is unaware of the surrounding JSON string context, a resolved value containing a double-quote character can break out of its string and inject additional JSON structure. When a connection is configured to use this mapper with a template that reflects a header whose value a publishing device can control (for example an MQTT 5 user property, an AMQP 1.0 application property, or a Kafka record header), an attacker able to publish on that connection can inject an inline _policy object. The inline policy overrides the administrator-configured policyId, letting the attacker assign an arbitrary access-control policy to the newly created digital twin — gaining full read/write access to it and potentially revoking the legitimate owner's access, with no administrator interaction. Exploitation requires all of the following: the connection uses the (non-default) ImplicitThingCreation mapper; its template reflects an attacker-controllable header; and, for the policy-override impact, the connection's authorization subjects are permitted to create policies (the default). Deployments that restrict the connection's subjects to thing creation only via the entity-creation configuration are not affected by the policy-override impact.

29d ago
CVE-2026-32773
MEDIUM· 6.1

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

apache
29d ago
CVE-2026-19219
HIGH· 8.1

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.

29d ago
CVE-2026-18672
HIGH· 7.5

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.

29d ago
CVE-2026-84175
NONE

In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the redirect target and without a hop limit. An authenticated user who is permitted to create a Thing, or who holds WRITE permission on an existing Thing, can thereby cause the Things service to issue arbitrary HTTP GET requests from inside the deployment's network — including to cloud instance-metadata endpoints and other internal services — and can use the differing error responses returned to the caller to enumerate internal services. Versions 2.4.0 to 2.5.x contain the same code, but are only affected where the operator explicitly enabled the WoT integration feature toggle, which is disabled by default in those versions.

29d ago
CVE-2026-53683
MEDIUM· 4.3

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

29d ago
CVE-2026-75528
HIGH· 7.2

The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to perform the plugin's standard dismiss-and-recheck workflow on a link submitted by the attacker via the WordPress comment author URL field, after which the attacker's HTTP server issues a redirect to a URL containing an HTML/JavaScript payload that is stored verbatim in the link log.

29d ago
CVE-2026-23591
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23590
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23589
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23588
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23587
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23586
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23585
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23584
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-23583
NONE

Rejected reason: Withdrawn by requester.

29d ago
CVE-2026-14828
HIGH· 8.8

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

29d ago
CVE-2025-7963
MEDIUM· 6.4

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000