Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97898 | UNKNOWN | — | Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier … | Sep 25, 2026 |
| CVE-2026-92106 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied … | Sep 25, 2026 |
| CVE-2026-97863 | UNKNOWN | — | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values … | Sep 25, 2026 |
| CVE-2026-92573 | MEDIUM | 6.5 | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON … | Sep 25, 2026 |
| CVE-2026-92564 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. … | Sep 25, 2026 |
| CVE-2026-92560 | HIGH | 7.5 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through … | Sep 25, 2026 |
| CVE-2026-92550 | HIGH | 7.5 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through … | Sep 25, 2026 |
| CVE-2026-88848 | MEDIUM | 4.2 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their … | Sep 25, 2026 |
| CVE-2026-86837 | MEDIUM | 5.3 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's … | Sep 25, 2026 |
| CVE-2026-80514 | MEDIUM | 5.3 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its … | Sep 25, 2026 |
| CVE-2026-6088 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow … | Sep 25, 2026 |
| CVE-2026-6087 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow … | Sep 25, 2026 |
| CVE-2026-6086 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow … | Sep 25, 2026 |
| CVE-2026-6085 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow … | Sep 25, 2026 |
| CVE-2026-6084 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/variants' that allow … | Sep 25, 2026 |
| CVE-2026-6083 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint ' /inventory/configuration/pricing-tiers' that … | Sep 25, 2026 |
| CVE-2026-6082 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/payment-methods' that allow … | Sep 25, 2026 |
| CVE-2026-96752 | HIGH | 7.2 | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in … | Sep 25, 2026 |
| CVE-2026-96568 | HIGH | 7.2 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and … | Sep 25, 2026 |
| CVE-2026-96448 | MEDIUM | 6.6 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the … | Sep 25, 2026 |
| CVE-2026-95866 | HIGH | 7.2 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 25, 2026 |
| CVE-2026-95864 | HIGH | 7.2 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to … | Sep 25, 2026 |
| CVE-2026-94573 | HIGH | 7.2 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and … | Sep 25, 2026 |
| CVE-2026-93901 | HIGH | 7.3 | The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the … | Sep 25, 2026 |
| CVE-2026-93747 | MEDIUM | 6.4 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This … | Sep 25, 2026 |