UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 14)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-19598
    Pods – Custom Content Types and Fields privilege escalation via auth bypass sc0ttkclark Pods – Custom Content Types and Fields ·
    • PoC PUBLIC
    CRITICAL 9.8
  2. CVE-2026-15748
    Forminator Forms arbitrary file upload allows remote code execution wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.8
  3. CVE-2026-78006
    The Events Calendar pre-auth remote code execution via widget unserialize stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
  4. CVE-2026-78159
    The Events Calendar remote code execution via widget parsing stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
  5. CVE-2026-54107
    Windows 10 Version 1607 race condition lets local users elevate privileges Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7
  6. CVE-2026-43813
    IOS and iPadOS code signing bypass allows malicious apps to run Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  7. CVE-2026-64725
    IOS and iPadOS out-of-bounds write can let a local app crash the device Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  8. CVE-2026-19650
    GitLab GraphQL GET-request mutation execution vulnerability GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  9. CVE-2026-69451
    Windows 10 Version 1607 use-after-free in WMI allows privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  10. CVE-2026-19760
    WP Fastest Cache – Stored XSS via Host header in Combine JS emrevona WP Fastest Cache – WordPress Cache Plugin ·
    HIGH 7.2
  11. CVE-2026-18978
    LiteSpeed Cache stored cross-site scripting via comments litespeedtech LiteSpeed Cache ·
    HIGH 7.2
  12. CVE-2026-83561
    Complianz GDPR/CCPA Cookie Consent Banner stored cross-site scripting via comments complianz Complianz GDPR/CCPA Cookie Consent Banner ·
    HIGH 7.2
  13. CVE-2026-78906
    Chrome ANGLE race condition remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  14. CVE-2026-85045
    Chrome V8 race condition allows remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  15. CVE-2015-5287
    Automatic Bug Reporting Tool symlink local privilege escalation Red Hat Automatic Bug Reporting Tool ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 7.8
  16. CVE-2026-46680
    Containerd runAsNonRoot bypass via large numeric User value containerd containerd ·
    • PoC PUBLIC
    HIGH 7.8
  17. CVE-2026-53362
    Linux Kernel IPv6 frag handling local privilege escalation Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  18. CVE-2026-49176
    Windows 10/Server privilege escalation in WalletService (local) Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  19. CVE-2026-54992
    Windows 10 Version 1607 heap-based buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  20. CVE-2026-58635
    Windows 10 Version 1809 Narrator Braille command injection local privilege elevation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
20 CVEs · page 14 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.