Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54499
Total
4309
Critical
16193
High
15930
Medium
CVE ID Severity Score Description Published
CVE-2026-97898 UNKNOWN — Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier … Sep 25, 2026
CVE-2026-92106 UNKNOWN — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied … Sep 25, 2026
CVE-2026-97863 UNKNOWN — The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values … Sep 25, 2026
CVE-2026-92573 MEDIUM 6.5 Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON … Sep 25, 2026
CVE-2026-92564 UNKNOWN — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. … Sep 25, 2026
CVE-2026-92560 HIGH 7.5 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through … Sep 25, 2026
CVE-2026-92550 HIGH 7.5 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through … Sep 25, 2026
CVE-2026-88848 MEDIUM 4.2 The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their … Sep 25, 2026
CVE-2026-86837 MEDIUM 5.3 The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's … Sep 25, 2026
CVE-2026-80514 MEDIUM 5.3 The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its … Sep 25, 2026
CVE-2026-6088 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow … Sep 25, 2026
CVE-2026-6087 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow … Sep 25, 2026
CVE-2026-6086 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow … Sep 25, 2026
CVE-2026-6085 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow … Sep 25, 2026
CVE-2026-6084 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/variants' that allow … Sep 25, 2026
CVE-2026-6083 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint ' /inventory/configuration/pricing-tiers' that … Sep 25, 2026
CVE-2026-6082 UNKNOWN — Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/payment-methods' that allow … Sep 25, 2026
CVE-2026-96752 HIGH 7.2 The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in … Sep 25, 2026
CVE-2026-96568 HIGH 7.2 The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and … Sep 25, 2026
CVE-2026-96448 MEDIUM 6.6 A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the … Sep 25, 2026
CVE-2026-95866 HIGH 7.2 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Sep 25, 2026
CVE-2026-95864 HIGH 7.2 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to … Sep 25, 2026
CVE-2026-94573 HIGH 7.2 The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and … Sep 25, 2026
CVE-2026-93901 HIGH 7.3 The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the … Sep 25, 2026
CVE-2026-93747 MEDIUM 6.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This … Sep 25, 2026