Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54755
Total
4323
Critical
16270
High
16026
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77193 | HIGH | 7.5 | The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` … | Sep 24, 2026 |
| CVE-2026-97181 | MEDIUM | 5.3 | GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. | Sep 24, 2026 |
| CVE-2026-87739 | UNKNOWN | — | An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an … | Sep 24, 2026 |
| CVE-2026-82077 | UNKNOWN | — | An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an … | Sep 24, 2026 |
| CVE-2026-81645 | MEDIUM | 5.9 | Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability. | Sep 24, 2026 |
| CVE-2026-11744 | UNKNOWN | — | An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC … | Sep 24, 2026 |
| CVE-2026-97177 | MEDIUM | 6.6 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to … | Sep 24, 2026 |
| CVE-2026-97176 | MEDIUM | 4.2 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client … | Sep 24, 2026 |
| CVE-2026-97168 | UNKNOWN | — | Rejected reason: it is a suggestion | Sep 24, 2026 |
| CVE-2026-93662 | MEDIUM | 4.3 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own … | Sep 24, 2026 |
| CVE-2026-93661 | LOW | 2.7 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting … | Sep 24, 2026 |
| CVE-2026-89005 | MEDIUM | 6.8 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is … | Sep 24, 2026 |
| CVE-2026-89004 | LOW | 2.7 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing … | Sep 24, 2026 |
| CVE-2026-89002 | MEDIUM | 6.8 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which … | Sep 24, 2026 |
| CVE-2026-88847 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against … | Sep 24, 2026 |
| CVE-2026-88846 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through … | Sep 24, 2026 |
| CVE-2026-88845 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated … | Sep 24, 2026 |
| CVE-2026-88843 | HIGH | 7.2 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, … | Sep 24, 2026 |
| CVE-2026-84151 | LOW | 3.5 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, … | Sep 24, 2026 |
| CVE-2026-82850 | MEDIUM | 4.3 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve … | Sep 24, 2026 |
| CVE-2026-82849 | MEDIUM | 4.3 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated … | Sep 24, 2026 |
| CVE-2026-82195 | MEDIUM | 6.5 | The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing … | Sep 24, 2026 |
| CVE-2026-80513 | HIGH | 7.5 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated … | Sep 24, 2026 |
| CVE-2026-80338 | MEDIUM | 6.8 | The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low … | Sep 24, 2026 |
| CVE-2026-74991 | MEDIUM | 6.8 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting … | Sep 24, 2026 |