Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97873 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation … | Oct 03, 2026 |
| CVE-2026-85515 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path … | Oct 03, 2026 |
| CVE-2026-71892 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption … | Oct 03, 2026 |
| CVE-2026-71891 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted … | Oct 03, 2026 |
| CVE-2026-71890 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded … | Oct 03, 2026 |
| CVE-2026-71889 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity … | Oct 03, 2026 |
| CVE-2026-71888 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes … | Oct 03, 2026 |
| CVE-2026-71887 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried … | Oct 03, 2026 |
| CVE-2026-71886 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the … | Oct 03, 2026 |
| CVE-2026-71885 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. … | Oct 03, 2026 |
| CVE-2026-71883 | UNKNOWN | — | In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, … | Oct 03, 2026 |
| CVE-2026-18040 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, … | Oct 03, 2026 |
| CVE-2026-92767 | MEDIUM | 6.4 | The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 … | Oct 03, 2026 |
| CVE-2026-92084 | CRITICAL | 9.1 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up … | Oct 03, 2026 |
| CVE-2026-104982 | MEDIUM | 4.3 | A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component … | Oct 03, 2026 |
| CVE-2026-97660 | HIGH | 7.2 | The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all … | Oct 03, 2026 |
| CVE-2026-97343 | MEDIUM | 4.3 | The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions … | Oct 03, 2026 |
| CVE-2026-96267 | HIGH | 7.5 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, … | Oct 03, 2026 |
| CVE-2026-94505 | HIGH | 8.1 | The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Oct 03, 2026 |
| CVE-2026-93896 | MEDIUM | 6.1 | The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the … | Oct 03, 2026 |
| CVE-2026-93889 | HIGH | 7.2 | The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up … | Oct 03, 2026 |
| CVE-2026-92974 | MEDIUM | 6.1 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions … | Oct 03, 2026 |
| CVE-2026-87115 | CRITICAL | 9.1 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in … | Oct 03, 2026 |
| CVE-2026-75028 | HIGH | 7.5 | The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up … | Oct 03, 2026 |
| CVE-2026-18443 | HIGH | 8.8 | The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in … | Oct 03, 2026 |