Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-17508 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being … | Oct 02, 2026 |
| CVE-2026-17507 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with … | Oct 02, 2026 |
| CVE-2026-12951 | MEDIUM | 6.5 | The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up … | Oct 02, 2026 |
| CVE-2026-103604 | UNKNOWN | — | Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote … | Oct 02, 2026 |
| CVE-2026-103603 | UNKNOWN | — | Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a … | Oct 02, 2026 |
| CVE-2026-103602 | UNKNOWN | — | Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, … | Oct 02, 2026 |
| CVE-2026-103601 | UNKNOWN | — | Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 … | Oct 02, 2026 |
| CVE-2026-103600 | UNKNOWN | — | Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause … | Oct 02, 2026 |
| CVE-2026-103426 | HIGH | 7.2 | The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due … | Oct 02, 2026 |
| CVE-2026-102772 | HIGH | 7.2 | The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, … | Oct 02, 2026 |
| CVE-2026-102002 | LOW | 3.1 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … | Oct 02, 2026 |
| CVE-2026-100182 | HIGH | 7.2 | The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, … | Oct 02, 2026 |
| CVE-2026-100107 | HIGH | 7.2 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, … | Oct 02, 2026 |
| CVE-2026-97219 | MEDIUM | 4.3 | The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a … | Oct 02, 2026 |
| CVE-2026-93698 | CRITICAL | 9.9 | Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin. | Oct 02, 2026 |
| CVE-2026-93697 | CRITICAL | 9.0 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | Oct 02, 2026 |
| CVE-2026-93029 | CRITICAL | 9.0 | There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | Oct 02, 2026 |
| CVE-2026-92924 | MEDIUM | 5.4 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to … | Oct 02, 2026 |
| CVE-2026-91020 | MEDIUM | 5.3 | The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item … | Oct 02, 2026 |
| CVE-2026-90987 | MEDIUM | 5.3 | The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a … | Oct 02, 2026 |
| CVE-2026-90952 | MEDIUM | 5.3 | The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to … | Oct 02, 2026 |
| CVE-2026-85005 | MEDIUM | 5.4 | The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any … | Oct 02, 2026 |
| CVE-2026-84740 | MEDIUM | 6.5 | The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering … | Oct 02, 2026 |
| CVE-2026-79618 | MEDIUM | 4.3 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level … | Oct 02, 2026 |
| CVE-2026-63569 | UNKNOWN | — | Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the … | Oct 02, 2026 |