Threat Intelligence Feed

Aggregating 7923 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-88847 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course MED · CVE-2026-88846 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled MED · CVE-2026-88845 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on HIGH · CVE-2026-88843 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings CVE-2026-84151 The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own m MED · CVE-2026-82850 The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate MED · CVE-2026-82849 The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre MED · CVE-2026-82195 The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret HIGH · CVE-2026-80513 The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes MED · CVE-2026-80338 The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users MED · CVE-2026-74991 The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su CVE-2026-14780 A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization MED · CVE-2026-97155 Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v CVE-2026-97152 Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport CVE-2026-97151 mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen HIGH · CVE-2026-96898 A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality MED · CVE-2026-96892 A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor CVE-2026-97149 In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU CRIT · CVE-2026-96891 A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel. MED · CVE-2026-96884 A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the MED · CVE-2026-96882 A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio MED · CVE-2026-96881 A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file MED · CVE-2026-97056 SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh HIGH · CVE-2026-97055 SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK MED · CVE-2026-96880 A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/ CVE-2026-96810 A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affec HIGH · CVE-2026-96803 A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBac MED · CVE-2026-96777 A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTa CRIT · CVE-2026-18467 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions MED · CVE-2026-96774 A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects MED · CVE-2026-96773 A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers:: MED · CVE-2026-96772 A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /ac MED · CVE-2026-96764 A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::G MED · CVE-2026-96763 A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the HIGH · CVE-2026-96762 A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegmen HIGH · CVE-2026-96751 A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. T MED · CVE-2026-96739 A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/up CRIT · CVE-2026-93577 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1 MED · CVE-2026-92874 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 1 CVE-2026-92628 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 1
5359 general 1013 advisories 725 research 547 vendor 279 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.