Threat Intelligence Feed

Aggregating 7967 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-88847 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course MED · CVE-2026-88846 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled MED · CVE-2026-88845 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on HIGH · CVE-2026-88843 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings CVE-2026-84151 The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own m MED · CVE-2026-82850 The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate MED · CVE-2026-82849 The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre MED · CVE-2026-82195 The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret HIGH · CVE-2026-80513 The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes MED · CVE-2026-80338 The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users MED · CVE-2026-74991 The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su CVE-2026-14780 A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization MED · CVE-2026-97155 Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v CVE-2026-97152 Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport CVE-2026-97151 mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen HIGH · CVE-2026-96898 A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality MED · CVE-2026-96892 A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor CVE-2026-97149 In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU CRIT · CVE-2026-96891 A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel. MED · CVE-2026-96884 A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the MED · CVE-2026-96882 A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio MED · CVE-2026-96881 A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file MED · CVE-2026-97056 SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh HIGH · CVE-2026-97055 SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK MED · CVE-2026-96880 A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/ CVE-2026-96810 A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affec HIGH · CVE-2026-96803 A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBac MED · CVE-2026-96777 A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTa CRIT · CVE-2026-18467 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions MED · CVE-2026-96774 A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects MED · CVE-2026-96773 A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers:: MED · CVE-2026-96772 A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /ac MED · CVE-2026-96764 A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::G MED · CVE-2026-96763 A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the HIGH · CVE-2026-96762 A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegmen HIGH · CVE-2026-96751 A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. T MED · CVE-2026-96739 A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/up CRIT · CVE-2026-93577 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1 MED · CVE-2026-92874 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 1 CVE-2026-92628 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 1
5395 general 1014 advisories 726 research 551 vendor 281 enterprise

Trending Vendors

Latest News

Hunting In Memory

Threat Hunters are charged with the difficult task of sifting through vast sources of diverse data to pinpoint adversarial activity at any stage in the attack.

Elastic Security Labs → Details

Data Breaches

No articles found.