Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54499
Total
4309
Critical
16193
High
15930
Medium
CVE ID Severity Score Description Published
CVE-2026-92799 MEDIUM 5.3 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up … Sep 25, 2026
CVE-2026-92746 MEDIUM 6.4 The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute … Sep 25, 2026
CVE-2026-92212 MEDIUM 6.1 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field … Sep 25, 2026
CVE-2026-89055 CRITICAL 9.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to … Sep 25, 2026
CVE-2026-84281 HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, … Sep 25, 2026
CVE-2026-84279 HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 … Sep 25, 2026
CVE-2026-83591 HIGH 7.2 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all … Sep 25, 2026
CVE-2026-78397 MEDIUM 4.0 The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its … Sep 25, 2026
CVE-2026-78394 MEDIUM 4.1 The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the … Sep 25, 2026
CVE-2026-78393 MEDIUM 6.1 The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its … Sep 25, 2026
CVE-2026-75553 LOW 2.4 Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from … Sep 25, 2026
CVE-2026-62062 HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1. Sep 25, 2026
CVE-2026-19775 MEDIUM 4.3 The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Sep 25, 2026
CVE-2026-14281 CRITICAL 9.8 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up … Sep 25, 2026
CVE-2026-97721 LOW 2.7 A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. … Sep 25, 2026
CVE-2026-97818 HIGH 8.6 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. Sep 25, 2026
CVE-2026-97764 LOW 3.7 django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of … Sep 25, 2026
CVE-2026-97737 HIGH 7.4 In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. Sep 25, 2026
CVE-2026-97736 MEDIUM 5.4 tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression. Sep 25, 2026
CVE-2026-97735 HIGH 8.0 ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders. Sep 25, 2026
CVE-2026-97732 MEDIUM 5.1 IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., … Sep 25, 2026
CVE-2025-14814 MEDIUM 6.4 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and … Sep 25, 2026
CVE-2026-97731 HIGH 7.1 MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates … Sep 25, 2026
CVE-2026-97730 HIGH 8.5 In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling … Sep 25, 2026
CVE-2026-97724 MEDIUM 4.3 A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of … Sep 25, 2026