Live feed

CVE Feed

Last 30 days — 14,226 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-4130
HIGH· 7.1

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

29d ago
CVE-2026-4129
HIGH· 8.1

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.

29d ago
CVE-2026-88924
HIGH· 7.0

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.

29d ago
CVE-2026-88898
MEDIUM· 6.5

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.

29d ago
CVE-2026-88897
MEDIUM· 5.9

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

29d ago
CVE-2026-88008
CRITICAL· 9.1

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.

traefik
29d ago
CVE-2026-88007
CRITICAL· 9.1

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.

traefik
29d ago
CVE-2026-88006
MEDIUM· 6.5

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.

openwebui
29d ago
CVE-2026-88005
MEDIUM· 6.5

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.

openwebui
29d ago
CVE-2026-88004
HIGH· 7.4

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially spoofing identity or forwarded routing data. This issue is fixed in 3.7.13.

traefik
29d ago
CVE-2026-85310
MEDIUM· 6.5

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

29d ago
CVE-2026-84821
HIGH· 7.5

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

29d ago
CVE-2026-84819
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

29d ago
CVE-2026-84816
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.

29d ago
CVE-2026-81805
HIGH· 8.1

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

29d ago
CVE-2026-81804
HIGH· 7.5

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

29d ago
CVE-2026-81803
HIGH· 7.5

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

29d ago
CVE-2026-81801
HIGH· 8.1

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

29d ago
CVE-2026-81800
CRITICAL· 9.3

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

29d ago
CVE-2026-81799
HIGH· 7.5

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

29d ago
CVE-2026-81796
HIGH· 7.3

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

29d ago
CVE-2026-81795
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

29d ago
CVE-2026-81794
HIGH· 7.5

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

29d ago
CVE-2026-81793
MEDIUM· 6.5

Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9.

29d ago
CVE-2026-81791
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

29d ago
CVE-2026-81789
HIGH· 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.

29d ago
CVE-2026-81788
MEDIUM· 6.3

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

29d ago
CVE-2026-81787
MEDIUM· 6.5

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

29d ago
CVE-2026-81786
HIGH· 7.5

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

29d ago
CVE-2026-81785
MEDIUM· 6.5

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

29d ago
CVE-2026-81784
HIGH· 8.1

Deserialization of Untrusted Data vulnerability in Marcin Wise Chat wise-chat allows Object Injection.This issue affects Wise Chat: from n/a through 3.4.2.

29d ago
CVE-2026-81783
HIGH· 7.1

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

29d ago
CVE-2026-81782
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

29d ago
CVE-2026-81275
MEDIUM· 6.5

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

29d ago
CVE-2026-78536
MEDIUM· 6.5

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

29d ago
CVE-2026-66674
MEDIUM· 5.6

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

29d ago
CVE-2026-66632
MEDIUM· 6.5

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

29d ago
CVE-2026-46387
HIGH· 7.5

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A crafted HTTP/2 DATA payload using a high compression ratio, such as gzip, deflate, or brotli compressed data, could cause Suricata to allocate excessive memory while decompressing the payload. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP2.

oisf
29d ago
CVE-2026-45747
HIGH· 7.5

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.

oisf
29d ago
CVE-2026-15461
MEDIUM· 5.3

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first member because its callbacks cast user_data directly to struct gnss_nmea0183_match_data . In the affected releases match_data was the second member (after const struct device dev), so it sat at a non-zero offset while gnss_nmea0183_match_init() initialized it at the correct address. The registered NMEA handlers instead pass the whole device data object (data->devices.gnss->data, offset 0), producing an offset-shifted type confusion between where state is initialized and where the parse callbacks read and write it. When NMEA sentences from the GNSS receiver are parsed, the GGA/RMC callbacks write parsed fix data into the wrong location within the struct, and the GSV callback (gnss_nmea0183_match_gsv_callback, active under CONFIG_GNSS_SATELLITES) reads its satellites pointer and bound from the wrong offsets — non-pointer bytes of struct hl78xx_gnss_data — and then writes parsed struct gnss_satellite entries through that bogus pointer. This is a write through an uninitialized/wild pointer with a garbage bound. The NMEA handlers are registered by default (CONFIG_HL78XX_GNSS_SOURCE_NMEA is the default GNSS source) on devices using the HL78xx GNSS. The driver runs in kernel context and the NMEA data originates from the GNSS radio front-end, so a party able to influence the GNSS signal (for example GNSS/GPS spoofing at radio proximity) can drive the kernel-side parser into the faulty write. The most likely impact is a crash (denial of service) because the bogus pointer resolves to a fixed near-NULL value, with adjacent-memory corruption possible on MMU-less targets. Confidentiality is not affected. Exploitation requires the satellites feature to be enabled and active, so attack complexity is high.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000