Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50228 | UNKNOWN | — | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP … | Sep 23, 2026 |
| CVE-2026-50227 | UNKNOWN | — | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). … | Sep 23, 2026 |
| CVE-2026-82331 | CRITICAL | 9.8 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source … | Sep 23, 2026 |
| CVE-2026-6831 | MEDIUM | 6.5 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due … | Sep 23, 2026 |
| CVE-2026-5924 | MEDIUM | 6.4 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up … | Sep 23, 2026 |
| CVE-2026-93528 | LOW | 3.7 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view … | Sep 23, 2026 |
| CVE-2026-93511 | MEDIUM | 5.3 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment … | Sep 23, 2026 |
| CVE-2026-93510 | MEDIUM | 4.3 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel … | Sep 23, 2026 |
| CVE-2026-93508 | HIGH | 8.1 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and … | Sep 23, 2026 |
| CVE-2026-93507 | LOW | 3.3 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users … | Sep 23, 2026 |
| CVE-2026-91077 | LOW | 2.7 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to … | Sep 23, 2026 |
| CVE-2026-91073 | MEDIUM | 6.8 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated … | Sep 23, 2026 |
| CVE-2026-91025 | MEDIUM | 4.3 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets … | Sep 23, 2026 |
| CVE-2026-91024 | MEDIUM | 6.8 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a … | Sep 23, 2026 |
| CVE-2026-90985 | MEDIUM | 5.3 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing … | Sep 23, 2026 |
| CVE-2026-90951 | LOW | 3.7 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds … | Sep 23, 2026 |
| CVE-2026-89331 | MEDIUM | 5.3 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose … | Sep 23, 2026 |
| CVE-2026-88997 | MEDIUM | 6.8 | The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute … | Sep 23, 2026 |
| CVE-2026-88929 | MEDIUM | 5.3 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to … | Sep 23, 2026 |
| CVE-2026-87981 | MEDIUM | 4.7 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing … | Sep 23, 2026 |
| CVE-2026-87979 | MEDIUM | 5.3 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers … | Sep 23, 2026 |
| CVE-2026-87074 | LOW | 3.7 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient … | Sep 23, 2026 |
| CVE-2026-87069 | LOW | 3.1 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction … | Sep 23, 2026 |
| CVE-2026-86842 | MEDIUM | 6.8 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access … | Sep 23, 2026 |
| CVE-2026-86785 | MEDIUM | 5.3 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to … | Sep 23, 2026 |