Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63568 | UNKNOWN | — | Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows … | Oct 02, 2026 |
| CVE-2026-63567 | UNKNOWN | — | Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES … | Oct 02, 2026 |
| CVE-2026-63566 | UNKNOWN | — | Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a … | Oct 02, 2026 |
| CVE-2026-1661 | MEDIUM | 4.3 | The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin … | Oct 02, 2026 |
| CVE-2026-16001 | UNKNOWN | — | Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion … | Oct 02, 2026 |
| CVE-2026-16000 | UNKNOWN | — | Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who … | Oct 02, 2026 |
| CVE-2026-15999 | UNKNOWN | — | Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an … | Oct 02, 2026 |
| CVE-2026-13413 | MEDIUM | 5.3 | The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing … | Oct 02, 2026 |
| CVE-2026-102565 | HIGH | 7.2 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 … | Oct 02, 2026 |
| CVE-2026-97318 | MEDIUM | 6.1 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting … | Oct 02, 2026 |
| CVE-2026-97317 | MEDIUM | 5.3 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public … | Oct 02, 2026 |
| CVE-2026-94298 | MEDIUM | 6.2 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in … | Oct 02, 2026 |
| CVE-2026-92820 | HIGH | 8.1 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the … | Oct 02, 2026 |
| CVE-2026-92174 | HIGH | 7.5 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter … | Oct 02, 2026 |
| CVE-2026-91828 | HIGH | 7.5 | The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that … | Oct 02, 2026 |
| CVE-2026-91023 | LOW | 3.1 | The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing … | Oct 02, 2026 |
| CVE-2026-91022 | MEDIUM | 6.8 | The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with … | Oct 02, 2026 |
| CVE-2026-90988 | MEDIUM | 5.3 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to … | Oct 02, 2026 |
| CVE-2026-90438 | HIGH | 7.2 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) … | Oct 02, 2026 |
| CVE-2026-85016 | MEDIUM | 6.8 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared … | Oct 02, 2026 |
| CVE-2026-85004 | MEDIUM | 4.3 | The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated … | Oct 02, 2026 |
| CVE-2026-84925 | MEDIUM | 6.1 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions … | Oct 02, 2026 |
| CVE-2026-81740 | MEDIUM | 5.3 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has … | Oct 02, 2026 |
| CVE-2026-78471 | MEDIUM | 5.4 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to … | Oct 02, 2026 |
| CVE-2026-15897 | HIGH | 8.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … | Oct 02, 2026 |