Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91792 | HIGH | 7.8 | When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause … | Sep 23, 2026 |
| CVE-2026-91791 | HIGH | 7.8 | When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause … | Sep 23, 2026 |
| CVE-2026-91790 | HIGH | 7.8 | When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the … | Sep 23, 2026 |
| CVE-2026-91789 | HIGH | 7.8 | Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an … | Sep 23, 2026 |
| CVE-2026-91788 | MEDIUM | 4.7 | When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious … | Sep 23, 2026 |
| CVE-2026-50228 | UNKNOWN | — | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP … | Sep 23, 2026 |
| CVE-2026-50227 | UNKNOWN | — | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). … | Sep 23, 2026 |
| CVE-2026-82331 | CRITICAL | 9.8 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source … | Sep 23, 2026 |
| CVE-2026-6831 | MEDIUM | 6.5 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due … | Sep 23, 2026 |
| CVE-2026-5924 | MEDIUM | 6.4 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up … | Sep 23, 2026 |
| CVE-2026-93528 | LOW | 3.7 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view … | Sep 23, 2026 |
| CVE-2026-93511 | MEDIUM | 5.3 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment … | Sep 23, 2026 |
| CVE-2026-93510 | MEDIUM | 4.3 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel … | Sep 23, 2026 |
| CVE-2026-93508 | HIGH | 8.1 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and … | Sep 23, 2026 |
| CVE-2026-93507 | LOW | 3.3 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users … | Sep 23, 2026 |
| CVE-2026-91077 | LOW | 2.7 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to … | Sep 23, 2026 |
| CVE-2026-91073 | MEDIUM | 6.8 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated … | Sep 23, 2026 |
| CVE-2026-91025 | MEDIUM | 4.3 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets … | Sep 23, 2026 |
| CVE-2026-91024 | MEDIUM | 6.8 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a … | Sep 23, 2026 |
| CVE-2026-90985 | MEDIUM | 5.3 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing … | Sep 23, 2026 |
| CVE-2026-90951 | LOW | 3.7 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds … | Sep 23, 2026 |
| CVE-2026-89331 | MEDIUM | 5.3 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose … | Sep 23, 2026 |
| CVE-2026-88997 | MEDIUM | 6.8 | The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute … | Sep 23, 2026 |
| CVE-2026-88929 | MEDIUM | 5.3 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to … | Sep 23, 2026 |
| CVE-2026-87981 | MEDIUM | 4.7 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing … | Sep 23, 2026 |