Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-63568 UNKNOWN — Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows … Oct 02, 2026
CVE-2026-63567 UNKNOWN — Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES … Oct 02, 2026
CVE-2026-63566 UNKNOWN — Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a … Oct 02, 2026
CVE-2026-1661 MEDIUM 4.3 The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin … Oct 02, 2026
CVE-2026-16001 UNKNOWN — Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion … Oct 02, 2026
CVE-2026-16000 UNKNOWN — Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who … Oct 02, 2026
CVE-2026-15999 UNKNOWN — Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an … Oct 02, 2026
CVE-2026-13413 MEDIUM 5.3 The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing … Oct 02, 2026
CVE-2026-102565 HIGH 7.2 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 … Oct 02, 2026
CVE-2026-97318 MEDIUM 6.1 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting … Oct 02, 2026
CVE-2026-97317 MEDIUM 5.3 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public … Oct 02, 2026
CVE-2026-94298 MEDIUM 6.2 The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in … Oct 02, 2026
CVE-2026-92820 HIGH 8.1 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the … Oct 02, 2026
CVE-2026-92174 HIGH 7.5 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter … Oct 02, 2026
CVE-2026-91828 HIGH 7.5 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that … Oct 02, 2026
CVE-2026-91023 LOW 3.1 The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing … Oct 02, 2026
CVE-2026-91022 MEDIUM 6.8 The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with … Oct 02, 2026
CVE-2026-90988 MEDIUM 5.3 The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to … Oct 02, 2026
CVE-2026-90438 HIGH 7.2 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) … Oct 02, 2026
CVE-2026-85016 MEDIUM 6.8 The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared … Oct 02, 2026
CVE-2026-85004 MEDIUM 4.3 The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated … Oct 02, 2026
CVE-2026-84925 MEDIUM 6.1 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions … Oct 02, 2026
CVE-2026-81740 MEDIUM 5.3 The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has … Oct 02, 2026
CVE-2026-78471 MEDIUM 5.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to … Oct 02, 2026
CVE-2026-15897 HIGH 8.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … Oct 02, 2026