Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54305
Total
4306
Critical
16147
High
15838
Medium
CVE ID Severity Score Description Published
CVE-2026-92995 MEDIUM 5.3 The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files … Sep 27, 2026
CVE-2026-92436 MEDIUM 5.3 The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that … Sep 27, 2026
CVE-2026-89006 MEDIUM 6.8 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the … Sep 27, 2026
CVE-2026-89003 MEDIUM 4.1 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing … Sep 27, 2026
CVE-2026-89001 MEDIUM 4.9 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or … Sep 27, 2026
CVE-2026-89000 MEDIUM 4.1 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before … Sep 27, 2026
CVE-2026-86841 MEDIUM 4.7 The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged … Sep 27, 2026
CVE-2026-86839 LOW 3.8 The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions … Sep 27, 2026
CVE-2026-86609 HIGH 8.8 The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in … Sep 27, 2026
CVE-2026-85002 MEDIUM 6.8 The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users … Sep 27, 2026
CVE-2026-84069 MEDIUM 5.3 The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using … Sep 27, 2026
CVE-2026-82841 MEDIUM 5.3 The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any … Sep 27, 2026
CVE-2026-81655 HIGH 7.5 The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in … Sep 27, 2026
CVE-2026-100746 HIGH 7.3 A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup … Sep 27, 2026
CVE-2026-100865 HIGH 8.8 Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes … Sep 27, 2026
CVE-2026-100864 HIGH 8.8 heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python … Sep 27, 2026
CVE-2026-100863 MEDIUM 5.0 Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader … Sep 27, 2026
CVE-2026-100862 MEDIUM 4.9 heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned … Sep 27, 2026
CVE-2026-100861 MEDIUM 5.0 heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can … Sep 27, 2026
CVE-2026-100860 MEDIUM 5.5 heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — … Sep 27, 2026
CVE-2026-100859 MEDIUM 6.5 Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's … Sep 27, 2026
CVE-2026-100858 MEDIUM 6.8 heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken … Sep 27, 2026
CVE-2026-100857 HIGH 8.0 AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media … Sep 27, 2026
CVE-2026-100856 HIGH 8.8 AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. … Sep 27, 2026
CVE-2026-100855 MEDIUM 6.5 AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. … Sep 27, 2026