CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2026-60106

    Last Modified: 17 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jul 2026
    Unknown

    CVE-2026-60107

    Last Modified: 17 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jul 2026
    7.5
    High

    CVE-2026-44840

    Last Modified: 10 Jul 2026

    Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without any escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks. Version 25.3.4 patches the issue.

    Published: 8 Jul 2026
    7.1
    High

    CVE-2026-41122

    Last Modified: 3 Aug 2026

    Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 8 Jul 2026
    9.1
    Critical

    CVE-2026-54061

    Last Modified: 10 Jul 2026

    Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.

    Published: 8 Jul 2026
    5.3
    Medium

    CVE-2026-15033

    Last Modified: 8 Jul 2026

    A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the component peerDependencies. This manipulation causes os command injection. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Jul 2026
    9.2
    Critical

    CVE-2026-58480

    Last Modified: 14 Jul 2026

    Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

    Published: 8 Jul 2026
    6.4
    Medium

    CVE-2026-6740

    Last Modified: 10 Jul 2026

    The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    7.2
    High

    CVE-2026-6820

    Last Modified: 8 Jul 2026

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    4.7
    Medium

    CVE-2026-12002

    Last Modified: 10 Jul 2026

    The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 8 Jul 2026
    5.3
    Medium

    CVE-2026-5459

    Last Modified: 8 Jul 2026

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.

    Published: 8 Jul 2026
    6.4
    Medium

    CVE-2026-6459

    Last Modified: 8 Jul 2026

    The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    7.5
    High

    CVE-2026-5356

    Last Modified: 10 Jul 2026

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. This makes it possible for unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded PaymentIntent token.

    Published: 8 Jul 2026
    9.8
    Critical

    CVE-2026-14454

    Last Modified: 9 Jul 2026

    Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

    Published: 8 Jul 2026
    5.4
    Medium

    CVE-2026-8315

    Last Modified: 10 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 8 Jul 2026
    6.1
    Medium

    CVE-2026-8310

    Last Modified: 10 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 8 Jul 2026
    9.8
    Critical

    CVE-2026-8307

    Last Modified: 10 Jul 2026

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 8 Jul 2026
    4.8
    Medium

    CVE-2026-6371

    Last Modified: 20 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored XSS. This issue affects LimRAD NAC: before 5.5.7.3.9.

    Published: 8 Jul 2026
    9.1
    Critical

    CVE-2026-41042

    Last Modified: 10 Jul 2026

    Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal environment, so the severity is low.

    Published: 8 Jul 2026
    8.1
    High

    CVE-2026-3688

    Last Modified: 9 Jul 2026

    The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.

    Published: 8 Jul 2026
    6.4
    Medium

    CVE-2026-6742

    Last Modified: 8 Jul 2026

    The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    6.4
    Medium

    CVE-2025-14785

    Last Modified: 10 Jul 2026

    The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `seedprodnestedmenuwidget` shortcode in all versions up to, and including, 6.20.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    7.5
    High

    CVE-2026-6854

    Last Modified: 8 Jul 2026

    The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Jul 2026
    6.3
    Medium

    CVE-2026-14250

    Last Modified: 10 Jul 2026

    The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

    Published: 8 Jul 2026
    4.9
    Medium

    CVE-2026-12936

    Last Modified: 10 Jul 2026

    The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Jul 2026
    7.5
    High

    CVE-2026-6230

    Last Modified: 9 Jul 2026

    The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Jul 2026
    7.2
    High

    CVE-2026-6818

    Last Modified: 8 Jul 2026

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2026
    3.9
    Low

    CVE-2026-15028

    Last Modified: 13 Aug 2026

    A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.

    Published: 8 Jul 2026
    3.7
    Low

    CVE-2026-15041

    Last Modified: 10 Jul 2026

    A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.

    Published: 8 Jul 2026
    8.5
    High

    CVE-2026-56003

    Last Modified: 10 Jul 2026

    A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.

    Published: 8 Jul 2026
    6.5
    Medium

    CVE-2026-6280

    Last Modified: 10 Jul 2026

    Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-13126

    Last Modified: 10 Jul 2026

    The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-13127

    Last Modified: 10 Jul 2026

    The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-13128

    Last Modified: 10 Jul 2026

    Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.

    Published: 8 Jul 2026
    8.2
    High

    CVE-2026-57239

    Last Modified: 5 Aug 2026

    The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57240

    Last Modified: 10 Jul 2026

    When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-13129

    Last Modified: 10 Jul 2026

    When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57238

    Last Modified: 10 Jul 2026

    After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.

    Published: 8 Jul 2026
    6.1
    Medium

    CVE-2026-57241

    Last Modified: 10 Jul 2026

    The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57242

    Last Modified: 10 Jul 2026

    The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.

    Published: 8 Jul 2026
    6.1
    Medium

    CVE-2026-57243

    Last Modified: 10 Jul 2026

    During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57245

    Last Modified: 10 Jul 2026

    When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field combinations. This results in the internal objects entering an invalid state. Eventually, during the destruction phase, an invalid pointer write occurred, causing the application to crash.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57246

    Last Modified: 10 Jul 2026

    When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57248

    Last Modified: 10 Jul 2026

    When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57249

    Last Modified: 10 Jul 2026

    After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the re-entry process, the application access invalid objects and crashed.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57251

    Last Modified: 10 Jul 2026

    The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper limit and consistency checks. Out-of-bounds access to the underlying array is exposed, ultimately leading to a crash of the application.

    Published: 8 Jul 2026
    6.1
    Medium

    CVE-2026-57253

    Last Modified: 10 Jul 2026

    An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57252

    Last Modified: 10 Jul 2026

    When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.

    Published: 8 Jul 2026
    7.8
    High

    CVE-2026-57254

    Last Modified: 10 Jul 2026

    There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.

    Published: 8 Jul 2026
    6.1
    Medium

    CVE-2026-57255

    Last Modified: 10 Jul 2026

    The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing the application.

    Published: 8 Jul 2026