Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54949
Total
4343
Critical
16375
High
16061
Medium
CVE ID Severity Score Description Published
CVE-2026-96548 MEDIUM 5.6 A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. … Sep 23, 2026
CVE-2026-96546 LOW 2.5 A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in … Sep 23, 2026
CVE-2026-96545 MEDIUM 4.4 An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to … Sep 23, 2026
CVE-2026-96541 HIGH 7.5 A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely … Sep 23, 2026
CVE-2026-95604 HIGH 7.5 Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. Sep 23, 2026
CVE-2026-95603 HIGH 7.2 Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. Sep 23, 2026
CVE-2026-95602 MEDIUM 6.5 Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH … Sep 23, 2026
CVE-2026-95601 CRITICAL 9.3 Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. Sep 23, 2026
CVE-2026-95600 MEDIUM 5.3 Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. Sep 23, 2026
CVE-2026-95593 HIGH 7.6 Editor SQL Injection in Ultimeter <= 3.0.8 versions. Sep 23, 2026
CVE-2026-95592 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. Sep 23, 2026
CVE-2026-95590 HIGH 7.1 Subscriber SQL Injection in Tainacan <= 1.2.0 versions. Sep 23, 2026
CVE-2026-95586 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. Sep 23, 2026
CVE-2026-95530 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. Sep 23, 2026
CVE-2026-95529 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. Sep 23, 2026
CVE-2026-95528 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. Sep 23, 2026
CVE-2026-95527 MEDIUM 6.5 Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. Sep 23, 2026
CVE-2026-95525 MEDIUM 6.5 Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. Sep 23, 2026
CVE-2026-95524 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. Sep 23, 2026
CVE-2026-95523 MEDIUM 6.5 Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. Sep 23, 2026
CVE-2026-95522 HIGH 7.6 Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. Sep 23, 2026
CVE-2026-95515 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. Sep 23, 2026
CVE-2026-95514 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. Sep 23, 2026
CVE-2026-95513 HIGH 7.5 Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. Sep 23, 2026
CVE-2026-94684 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. Sep 23, 2026