Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16264 | MEDIUM | 6.5 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to … | Sep 23, 2026 |
| CVE-2026-14321 | HIGH | 8.2 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated … | Sep 23, 2026 |
| CVE-2025-15696 | MEDIUM | 6.8 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing … | Sep 23, 2026 |
| CVE-2022-4997 | HIGH | 8.6 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to … | Sep 23, 2026 |
| CVE-2026-96258 | MEDIUM | 4.3 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of … | Sep 23, 2026 |
| CVE-2026-96257 | CRITICAL | 10.0 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. … | Sep 23, 2026 |
| CVE-2026-95958 | LOW | 3.3 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing … | Sep 23, 2026 |
| CVE-2026-95957 | MEDIUM | 4.3 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of … | Sep 23, 2026 |
| CVE-2026-95930 | MEDIUM | 6.3 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API … | Sep 23, 2026 |
| CVE-2026-95929 | MEDIUM | 6.3 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API … | Sep 23, 2026 |
| CVE-2026-91777 | HIGH | 7.5 | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are … | Sep 23, 2026 |
| CVE-2026-91776 | HIGH | 7.5 | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use … | Sep 23, 2026 |
| CVE-2026-89425 | HIGH | 7.5 | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has … | Sep 23, 2026 |
| CVE-2026-95928 | MEDIUM | 5.5 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict … | Sep 23, 2026 |
| CVE-2026-95927 | HIGH | 7.3 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument … | Sep 23, 2026 |
| CVE-2026-95926 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of … | Sep 23, 2026 |
| CVE-2026-96273 | MEDIUM | 5.5 | Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious … | Sep 23, 2026 |
| CVE-2026-96272 | HIGH | 7.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE … | Sep 23, 2026 |
| CVE-2026-96271 | HIGH | 7.1 | Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by … | Sep 23, 2026 |
| CVE-2026-95925 | HIGH | 7.3 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of … | Sep 23, 2026 |
| CVE-2026-95924 | HIGH | 7.3 | A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the … | Sep 23, 2026 |
| CVE-2026-95897 | MEDIUM | 5.5 | A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such … | Sep 23, 2026 |
| CVE-2026-95868 | MEDIUM | 6.3 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the … | Sep 23, 2026 |
| CVE-2026-95833 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument … | Sep 23, 2026 |
| CVE-2026-95830 | MEDIUM | 6.3 | A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the file /post_upload.php. The manipulation of … | Sep 23, 2026 |