Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-82381 MEDIUM 5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store … Sep 28, 2026
CVE-2026-82380 HIGH 8.1 Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, … Sep 28, 2026
CVE-2026-82379 HIGH 7.7 Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the … Sep 28, 2026
CVE-2026-82378 CRITICAL 9.0 Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a … Sep 28, 2026
CVE-2026-82377 CRITICAL 9.9 Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC … Sep 28, 2026
CVE-2026-82376 HIGH 7.7 Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to … Sep 28, 2026
CVE-2026-82375 HIGH 7.4 Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen … Sep 28, 2026
CVE-2026-82348 HIGH 7.7 Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources … Sep 28, 2026
CVE-2026-101013 HIGH 7.3 A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the … Sep 28, 2026
CVE-2026-101012 HIGH 7.3 A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument … Sep 28, 2026
CVE-2026-101011 MEDIUM 4.7 A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain … Sep 28, 2026
CVE-2026-101010 MEDIUM 4.7 A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the … Sep 28, 2026
CVE-2026-93000 MEDIUM 6.8 The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is … Sep 28, 2026
CVE-2026-92996 MEDIUM 5.3 The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check … Sep 28, 2026
CVE-2026-89411 MEDIUM 5.3 The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing … Sep 28, 2026
CVE-2026-89303 MEDIUM 6.4 The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any … Sep 28, 2026
CVE-2026-89300 MEDIUM 5.3 The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert … Sep 28, 2026
CVE-2026-88828 MEDIUM 5.4 The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of … Sep 28, 2026
CVE-2026-86838 MEDIUM 5.3 The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to … Sep 28, 2026
CVE-2026-84744 MEDIUM 6.5 The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered … Sep 28, 2026
CVE-2026-101009 HIGH 8.4 A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip … Sep 28, 2026
CVE-2026-101008 CRITICAL 9.1 A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. … Sep 28, 2026
CVE-2026-101007 HIGH 8.4 A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database … Sep 28, 2026
CVE-2026-101006 MEDIUM 4.3 A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission … Sep 28, 2026
CVE-2026-101005 HIGH 7.3 A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The … Sep 28, 2026