Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54949
Total
4343
Critical
16375
High
16061
Medium
CVE ID Severity Score Description Published
CVE-2026-19532 MEDIUM 5.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: … Sep 24, 2026
CVE-2026-16302 MEDIUM 4.3 The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the … Sep 24, 2026
CVE-2026-97179 MEDIUM 4.3 A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher … Sep 24, 2026
CVE-2026-79680 UNKNOWN — Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the … Sep 24, 2026
CVE-2026-4638 UNKNOWN — PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, … Sep 24, 2026
CVE-2026-92905 MEDIUM 5.3 ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed … Sep 24, 2026
CVE-2026-57590 HIGH 8.1 A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has … Sep 24, 2026
CVE-2026-4637 UNKNOWN — Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource … Sep 24, 2026
CVE-2026-18335 MEDIUM 5.4 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, … Sep 24, 2026
CVE-2026-15731 MEDIUM 6.4 The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up … Sep 24, 2026
CVE-2026-12227 CRITICAL 9.8 The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` … Sep 24, 2026
CVE-2026-97185 HIGH 7.8 A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into … Sep 24, 2026
CVE-2026-85682 HIGH 8.8 The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the … Sep 24, 2026
CVE-2026-78313 MEDIUM 6.5 Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-78312 CRITICAL 9.1 Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-78311 HIGH 8.8 SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-78310 MEDIUM 4.3 Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-78309 HIGH 8.8 SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-78308 CRITICAL 9.8 Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. Sep 24, 2026
CVE-2026-77193 HIGH 7.5 The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` … Sep 24, 2026
CVE-2026-97181 MEDIUM 5.3 GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. Sep 24, 2026
CVE-2026-87739 UNKNOWN — An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an … Sep 24, 2026
CVE-2026-82077 UNKNOWN — An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an … Sep 24, 2026
CVE-2026-81645 MEDIUM 5.9 Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability. Sep 24, 2026
CVE-2026-11744 UNKNOWN — An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC … Sep 24, 2026