CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2026-28145

    Last Modified: 31 Jul 2026

    Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

    Published: 31 Jul 2026
    9.8
    Critical

    CVE-2026-17561

    Last Modified: 20 Aug 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-15227

    Last Modified: 31 Jul 2026

    Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-18358

    Last Modified: 13 Aug 2026

    A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.

    Published: 31 Jul 2026
    5.1
    Medium

    CVE-2026-46594

    Last Modified: 31 Jul 2026

    A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.

    Published: 31 Jul 2026
    8.6
    High

    CVE-2026-46593

    Last Modified: 31 Jul 2026

    A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

    Published: 31 Jul 2026
    6.9
    Medium

    CVE-2025-67651

    Last Modified: 31 Jul 2026

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.

    Published: 31 Jul 2026
    8.6
    High

    CVE-2025-67650

    Last Modified: 31 Jul 2026

    An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

    Published: 31 Jul 2026
    9.3
    Critical

    CVE-2025-67649

    Last Modified: 31 Jul 2026

    A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

    Published: 31 Jul 2026
    Unknown

    CVE-2026-68574

    Last Modified: 31 Jul 2026

    Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.

    Published: 31 Jul 2026
    Unknown

    CVE-2026-68575

    Last Modified: 31 Jul 2026

    Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.

    Published: 31 Jul 2026
    Unknown

    CVE-2026-68576

    Last Modified: 31 Jul 2026

    Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.

    Published: 31 Jul 2026
    Unknown

    CVE-2026-68577

    Last Modified: 31 Jul 2026

    Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.

    Published: 31 Jul 2026
    6.5
    Medium

    CVE-2026-44615

    Last Modified: 31 Jul 2026

    Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved,                   written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

    Published: 31 Jul 2026
    3.7
    Low

    CVE-2026-18569

    Last Modified: 4 Aug 2026

    A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-64607

    Last Modified: 13 Aug 2026

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

    Published: 31 Jul 2026
    8.1
    High

    CVE-2026-62391

    Last Modified: 31 Jul 2026

    The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-17567

    Last Modified: 31 Jul 2026

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account.

    Published: 31 Jul 2026
    7.2
    High

    CVE-2026-16843

    Last Modified: 4 Aug 2026

    Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

    Published: 31 Jul 2026
    8.5
    High

    CVE-2026-10079

    Last Modified: 31 Jul 2026

    A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-11770

    Last Modified: 18 Aug 2026

    A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-15722

    Last Modified: 18 Aug 2026

    A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-18436

    Last Modified: 2 Aug 2026

    The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-18437

    Last Modified: 2 Aug 2026

    The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.

    Published: 31 Jul 2026
    8.1
    High

    CVE-2026-65313

    Last Modified: 2 Aug 2026

    A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

    Published: 31 Jul 2026
    5.3
    Medium

    CVE-2026-65311

    Last Modified: 2 Aug 2026

    The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-65310

    Last Modified: 2 Aug 2026

    ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-65309

    Last Modified: 2 Aug 2026

    ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

    Published: 31 Jul 2026
    4.9
    Medium

    CVE-2026-16105

    Last Modified: 31 Aug 2026

    A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.

    Published: 31 Jul 2026
    9.8
    Critical

    CVE-2026-14919

    Last Modified: 3 Aug 2026

    The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

    Published: 31 Jul 2026
    3.7
    Low

    CVE-2026-14862

    Last Modified: 4 Aug 2026

    The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.

    Published: 31 Jul 2026
    8.8
    High

    CVE-2026-13609

    Last Modified: 31 Jul 2026

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9's front-end display surfaces, resulting in stored cross-site scripting that executes in the browser of any user, including an administrator, who views a page displaying the submitted value.

    Published: 31 Jul 2026
    5.4
    Medium

    CVE-2026-12697

    Last Modified: 31 Jul 2026

    The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

    Published: 31 Jul 2026
    8.1
    High

    CVE-2026-12695

    Last Modified: 3 Aug 2026

    The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

    Published: 31 Jul 2026
    4.3
    Medium

    CVE-2026-12376

    Last Modified: 3 Aug 2026

    The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results.

    Published: 31 Jul 2026
    3.5
    Low

    CVE-2026-13393

    Last Modified: 31 Jul 2026

    The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

    Published: 31 Jul 2026
    7.2
    High

    CVE-2026-13392

    Last Modified: 31 Jul 2026

    The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.

    Published: 31 Jul 2026
    8.6
    High

    CVE-2026-12721

    Last Modified: 31 Jul 2026

    The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-12720

    Last Modified: 31 Jul 2026

    The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.

    Published: 31 Jul 2026
    8.1
    High

    CVE-2026-12251

    Last Modified: 3 Aug 2026

    The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a role exists and a role-selection field is present on a published registration form.

    Published: 31 Jul 2026
    5.4
    Medium

    CVE-2026-8155

    Last Modified: 4 Aug 2026

    The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

    Published: 31 Jul 2026
    3.7
    Low

    CVE-2026-15381

    Last Modified: 31 Jul 2026

    The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

    Published: 31 Jul 2026
    8.1
    High

    CVE-2026-15258

    Last Modified: 4 Aug 2026

    The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

    Published: 31 Jul 2026
    6.5
    Medium

    CVE-2026-15209

    Last Modified: 7 Aug 2026

    The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-15048

    Last Modified: 31 Jul 2026

    The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

    Published: 31 Jul 2026
    6.5
    Medium

    CVE-2026-14931

    Last Modified: 4 Aug 2026

    The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.

    Published: 31 Jul 2026
    7.5
    High

    CVE-2026-14930

    Last Modified: 31 Jul 2026

    The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

    Published: 31 Jul 2026
    4.3
    Medium

    CVE-2026-14929

    Last Modified: 3 Aug 2026

    The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

    Published: 31 Jul 2026
    6.5
    Medium

    CVE-2026-14928

    Last Modified: 3 Aug 2026

    The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.

    Published: 31 Jul 2026
    3.7
    Low

    CVE-2026-14927

    Last Modified: 3 Aug 2026

    The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

    Published: 31 Jul 2026