Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-97637 CRITICAL 9.8 The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. … Oct 02, 2026
CVE-2026-97634 MEDIUM 6.5 The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, … Oct 02, 2026
CVE-2026-97342 HIGH 7.2 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in … Oct 02, 2026
CVE-2026-97338 MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to … Oct 02, 2026
CVE-2026-97336 HIGH 7.2 The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to … Oct 02, 2026
CVE-2026-96871 HIGH 7.2 The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due … Oct 02, 2026
CVE-2026-96647 MEDIUM 6.4 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up … Oct 02, 2026
CVE-2026-96578 HIGH 7.2 The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up … Oct 02, 2026
CVE-2026-96567 HIGH 7.2 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 … Oct 02, 2026
CVE-2026-96566 HIGH 7.2 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions … Oct 02, 2026
CVE-2026-95817 HIGH 7.2 The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 … Oct 02, 2026
CVE-2026-95670 HIGH 7.2 The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and … Oct 02, 2026
CVE-2026-94432 MEDIUM 5.3 The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … Oct 02, 2026
CVE-2026-93880 MEDIUM 6.1 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up … Oct 02, 2026
CVE-2026-93756 HIGH 7.2 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message … Oct 02, 2026
CVE-2026-63578 UNKNOWN — Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can … Oct 02, 2026
CVE-2026-63577 UNKNOWN — Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or … Oct 02, 2026
CVE-2026-63576 UNKNOWN — Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to … Oct 02, 2026
CVE-2026-63575 UNKNOWN — Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who … Oct 02, 2026
CVE-2026-63574 UNKNOWN — Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp … Oct 02, 2026
CVE-2026-63573 UNKNOWN — Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker … Oct 02, 2026
CVE-2026-63572 UNKNOWN — Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can … Oct 02, 2026
CVE-2026-63571 UNKNOWN — Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before … Oct 02, 2026
CVE-2026-63570 UNKNOWN — Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted … Oct 02, 2026
CVE-2026-18036 UNKNOWN — In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so … Oct 02, 2026