Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-89133 UNKNOWN — wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is … Sep 27, 2026
CVE-2026-89102 UNKNOWN — In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. … Sep 27, 2026
CVE-2026-15442 UNKNOWN — In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead … Sep 27, 2026
CVE-2026-94419 UNKNOWN — Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() … Sep 27, 2026
CVE-2026-94418 UNKNOWN — Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged … Sep 27, 2026
CVE-2026-100741 CRITICAL 9.8 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run … Sep 27, 2026
CVE-2026-97319 MEDIUM 6.8 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which … Sep 27, 2026
CVE-2026-97227 MEDIUM 5.9 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a … Sep 27, 2026
CVE-2026-96899 MEDIUM 6.8 The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it … Sep 27, 2026
CVE-2026-96897 MEDIUM 5.3 The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out … Sep 27, 2026
CVE-2026-96896 HIGH 7.2 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing … Sep 27, 2026
CVE-2026-96895 MEDIUM 6.8 The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when … Sep 27, 2026
CVE-2026-92995 MEDIUM 5.3 The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files … Sep 27, 2026
CVE-2026-92436 MEDIUM 5.3 The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that … Sep 27, 2026
CVE-2026-89006 MEDIUM 6.8 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the … Sep 27, 2026
CVE-2026-89003 MEDIUM 4.1 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing … Sep 27, 2026
CVE-2026-89001 MEDIUM 4.9 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or … Sep 27, 2026
CVE-2026-89000 MEDIUM 4.1 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before … Sep 27, 2026
CVE-2026-86841 MEDIUM 4.7 The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged … Sep 27, 2026
CVE-2026-86839 LOW 3.8 The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions … Sep 27, 2026
CVE-2026-86609 HIGH 8.8 The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in … Sep 27, 2026
CVE-2026-85002 MEDIUM 6.8 The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users … Sep 27, 2026
CVE-2026-84069 MEDIUM 5.3 The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using … Sep 27, 2026
CVE-2026-82841 MEDIUM 5.3 The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any … Sep 27, 2026
CVE-2026-81655 HIGH 7.5 The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in … Sep 27, 2026