Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97177 | MEDIUM | 6.6 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to … | Sep 24, 2026 |
| CVE-2026-97176 | MEDIUM | 4.2 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client … | Sep 24, 2026 |
| CVE-2026-97168 | UNKNOWN | — | Rejected reason: it is a suggestion | Sep 24, 2026 |
| CVE-2026-93662 | MEDIUM | 4.3 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own … | Sep 24, 2026 |
| CVE-2026-93661 | LOW | 2.7 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting … | Sep 24, 2026 |
| CVE-2026-89005 | MEDIUM | 6.8 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is … | Sep 24, 2026 |
| CVE-2026-89004 | LOW | 2.7 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing … | Sep 24, 2026 |
| CVE-2026-89002 | MEDIUM | 6.8 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which … | Sep 24, 2026 |
| CVE-2026-88847 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against … | Sep 24, 2026 |
| CVE-2026-88846 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through … | Sep 24, 2026 |
| CVE-2026-88845 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated … | Sep 24, 2026 |
| CVE-2026-88843 | HIGH | 7.2 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, … | Sep 24, 2026 |
| CVE-2026-84151 | LOW | 3.5 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, … | Sep 24, 2026 |
| CVE-2026-82850 | MEDIUM | 4.3 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve … | Sep 24, 2026 |
| CVE-2026-82849 | MEDIUM | 4.3 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated … | Sep 24, 2026 |
| CVE-2026-82195 | MEDIUM | 6.5 | The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing … | Sep 24, 2026 |
| CVE-2026-80513 | HIGH | 7.5 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated … | Sep 24, 2026 |
| CVE-2026-80338 | MEDIUM | 6.8 | The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low … | Sep 24, 2026 |
| CVE-2026-74991 | MEDIUM | 6.8 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting … | Sep 24, 2026 |
| CVE-2026-14780 | UNKNOWN | — | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user … | Sep 24, 2026 |
| CVE-2026-97155 | MEDIUM | 6.5 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins … | Sep 24, 2026 |
| CVE-2026-97152 | UNKNOWN | — | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version … | Sep 24, 2026 |
| CVE-2026-97151 | UNKNOWN | — | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an … | Sep 24, 2026 |
| CVE-2026-96898 | HIGH | 7.3 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component … | Sep 24, 2026 |
| CVE-2026-96892 | MEDIUM | 4.3 | A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of … | Sep 24, 2026 |