Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29528
Total
2302
Critical
8845
High
9186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-36568 | HIGH | 7.8 | Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through … | Apr 17, 2026 |
| CVE-2025-15625 | UNKNOWN | — | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. | Apr 17, 2026 |
| CVE-2025-15624 | UNKNOWN | — | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary … | Apr 17, 2026 |
| CVE-2025-15623 | UNKNOWN | — | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty … | Apr 17, 2026 |
| CVE-2025-15622 | UNKNOWN | — | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the … | Apr 17, 2026 |
| CVE-2026-6451 | MEDIUM | 4.3 | The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation … | Apr 17, 2026 |
| CVE-2026-40002 | MEDIUM | 5.0 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for … | Apr 17, 2026 |
| CVE-2026-33392 | HIGH | 7.2 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | Apr 17, 2026 |
| CVE-2026-23853 | HIGH | 8.4 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … | Apr 17, 2026 |
| CVE-2026-6443 | CRITICAL | 9.8 | The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold … | Apr 17, 2026 |
| CVE-2026-6441 | MEDIUM | 4.3 | The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any … | Apr 17, 2026 |
| CVE-2026-4659 | HIGH | 7.5 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and … | Apr 17, 2026 |
| CVE-2026-6482 | UNKNOWN | — | The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a … | Apr 17, 2026 |
| CVE-2026-6421 | HIGH | 7.0 | A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads … | Apr 17, 2026 |
| CVE-2026-5797 | MEDIUM | 5.3 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to … | Apr 17, 2026 |
| CVE-2026-35496 | LOW | 2.7 | A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should … | Apr 17, 2026 |
| CVE-2026-34018 | MEDIUM | 6.3 | An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. | Apr 17, 2026 |
| CVE-2026-21719 | HIGH | 7.2 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS … | Apr 17, 2026 |
| CVE-2026-6080 | MEDIUM | 6.5 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on … | Apr 17, 2026 |
| CVE-2026-5807 | HIGH | 7.5 | Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single … | Apr 17, 2026 |
| CVE-2026-5502 | MEDIUM | 5.3 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including … | Apr 17, 2026 |
| CVE-2026-5427 | MEDIUM | 5.3 | The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks … | Apr 17, 2026 |
| CVE-2026-5234 | MEDIUM | 5.3 | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the … | Apr 17, 2026 |
| CVE-2026-4853 | MEDIUM | 4.9 | The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and … | Apr 17, 2026 |
| CVE-2026-3330 | MEDIUM | 4.9 | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions … | Apr 17, 2026 |