Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-96548 | MEDIUM | 5.6 | A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. … | Sep 23, 2026 |
| CVE-2026-96546 | LOW | 2.5 | A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in … | Sep 23, 2026 |
| CVE-2026-96545 | MEDIUM | 4.4 | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to … | Sep 23, 2026 |
| CVE-2026-96541 | HIGH | 7.5 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely … | Sep 23, 2026 |
| CVE-2026-95604 | HIGH | 7.5 | Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. | Sep 23, 2026 |
| CVE-2026-95603 | HIGH | 7.2 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | Sep 23, 2026 |
| CVE-2026-95602 | MEDIUM | 6.5 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH … | Sep 23, 2026 |
| CVE-2026-95601 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. | Sep 23, 2026 |
| CVE-2026-95600 | MEDIUM | 5.3 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | Sep 23, 2026 |
| CVE-2026-95593 | HIGH | 7.6 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. | Sep 23, 2026 |
| CVE-2026-95592 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | Sep 23, 2026 |
| CVE-2026-95590 | HIGH | 7.1 | Subscriber SQL Injection in Tainacan <= 1.2.0 versions. | Sep 23, 2026 |
| CVE-2026-95586 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | Sep 23, 2026 |
| CVE-2026-95530 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. | Sep 23, 2026 |
| CVE-2026-95529 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | Sep 23, 2026 |
| CVE-2026-95528 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | Sep 23, 2026 |
| CVE-2026-95527 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | Sep 23, 2026 |
| CVE-2026-95525 | MEDIUM | 6.5 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | Sep 23, 2026 |
| CVE-2026-95524 | MEDIUM | 5.3 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | Sep 23, 2026 |
| CVE-2026-95523 | MEDIUM | 6.5 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | Sep 23, 2026 |
| CVE-2026-95522 | HIGH | 7.6 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | Sep 23, 2026 |
| CVE-2026-95515 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | Sep 23, 2026 |
| CVE-2026-95514 | MEDIUM | 5.3 | Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. | Sep 23, 2026 |
| CVE-2026-95513 | HIGH | 7.5 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. | Sep 23, 2026 |
| CVE-2026-94684 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. | Sep 23, 2026 |