CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-66641

    Last Modified: 24 Aug 2026

    Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-66640

    Last Modified: 21 Aug 2026

    Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-66639

    Last Modified: 21 Aug 2026

    Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-66638

    Last Modified: 24 Aug 2026

    Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-66637

    Last Modified: 18 Aug 2026

    Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-66636

    Last Modified: 24 Aug 2026

    Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.

    Published: 18 Aug 2026
    7.4
    High

    CVE-2026-66635

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-66634

    Last Modified: 21 Aug 2026

    Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-66633

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-66629

    Last Modified: 18 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.

    Published: 18 Aug 2026
    9.9
    Critical

    CVE-2026-66627

    Last Modified: 7 Sept 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-66622

    Last Modified: 18 Aug 2026

    Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-66621

    Last Modified: 25 Aug 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.

    Published: 18 Aug 2026
    7.2
    High

    CVE-2026-66620

    Last Modified: 21 Aug 2026

    Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

    Published: 18 Aug 2026
    7.2
    High

    CVE-2026-32553

    Last Modified: 18 Aug 2026

    Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-32549

    Last Modified: 18 Aug 2026

    Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-32547

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-32481

    Last Modified: 18 Aug 2026

    Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

    Published: 18 Aug 2026
    9.9
    Critical

    CVE-2026-32474

    Last Modified: 21 Aug 2026

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

    Published: 18 Aug 2026
    7.2
    High

    CVE-2026-32473

    Last Modified: 21 Aug 2026

    Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-32472

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-32470

    Last Modified: 18 Aug 2026

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-32468

    Last Modified: 24 Aug 2026

    Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

    Published: 18 Aug 2026
    6
    Medium

    CVE-2026-32467

    Last Modified: 21 Aug 2026

    Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

    Published: 18 Aug 2026
    8.5
    High

    CVE-2026-32466

    Last Modified: 21 Aug 2026

    Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-32465

    Last Modified: 18 Aug 2026

    Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-32464

    Last Modified: 21 Aug 2026

    Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

    Published: 18 Aug 2026
    9.9
    Critical

    CVE-2026-32463

    Last Modified: 21 Aug 2026

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

    Published: 18 Aug 2026
    9.9
    Critical

    CVE-2026-32444

    Last Modified: 21 Aug 2026

    Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-32333

    Last Modified: 18 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-28571

    Last Modified: 18 Aug 2026

    Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-28570

    Last Modified: 21 Aug 2026

    Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-28569

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-28568

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-28567

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

    Published: 18 Aug 2026
    9.6
    Critical

    CVE-2026-28192

    Last Modified: 24 Aug 2026

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-28191

    Last Modified: 1 Sept 2026

    Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0.

    Published: 18 Aug 2026
    6
    Medium

    CVE-2026-17084

    Last Modified: 10 Sept 2026

    The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

    Published: 18 Aug 2026
    Unknown

    CVE-2026-75890

    Last Modified: 18 Aug 2026

    Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.

    Published: 18 Aug 2026
    Unknown

    CVE-2026-73692

    Last Modified: 18 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 18 Aug 2026
    7.7
    High

    CVE-2026-50575

    Last Modified: 21 Aug 2026

    BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-24301

    Last Modified: 10 Sept 2026

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

    Published: 18 Aug 2026
    5.3
    Medium

    CVE-2026-16309

    Last Modified: 21 Aug 2026

    Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7.

    Published: 18 Aug 2026
    8.7
    High

    CVE-2026-45532

    Last Modified: 18 Aug 2026

    DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.

    Published: 18 Aug 2026
    8.6
    High

    CVE-2026-75783

    Last Modified: 18 Aug 2026

    A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.

    Published: 18 Aug 2026
    5.2
    Medium

    CVE-2026-18751

    Last Modified: 19 Aug 2026

    External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74989

    Last Modified: 1 Sept 2026

    Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74988

    Last Modified: 1 Sept 2026

    Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.1
    Critical

    CVE-2026-74986

    Last Modified: 25 Aug 2026

    Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74985

    Last Modified: 25 Aug 2026

    Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026