Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77765 | MEDIUM | 5.3 | The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway … | Sep 23, 2026 |
| CVE-2026-75799 | CRITICAL | 9.0 | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated … | Sep 23, 2026 |
| CVE-2026-19438 | HIGH | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876. | Sep 23, 2026 |
| CVE-2026-18365 | MEDIUM | 4.3 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level … | Sep 23, 2026 |
| CVE-2026-18364 | MEDIUM | 4.3 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level … | Sep 23, 2026 |
| CVE-2026-16264 | MEDIUM | 6.5 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to … | Sep 23, 2026 |
| CVE-2026-14321 | HIGH | 8.2 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated … | Sep 23, 2026 |
| CVE-2025-15696 | MEDIUM | 6.8 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing … | Sep 23, 2026 |
| CVE-2022-4997 | HIGH | 8.6 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to … | Sep 23, 2026 |
| CVE-2026-96258 | MEDIUM | 4.3 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of … | Sep 23, 2026 |
| CVE-2026-96257 | CRITICAL | 10.0 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. … | Sep 23, 2026 |
| CVE-2026-95958 | LOW | 3.3 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing … | Sep 23, 2026 |
| CVE-2026-95957 | MEDIUM | 4.3 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of … | Sep 23, 2026 |
| CVE-2026-95930 | MEDIUM | 6.3 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API … | Sep 23, 2026 |
| CVE-2026-95929 | MEDIUM | 6.3 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API … | Sep 23, 2026 |
| CVE-2026-91777 | HIGH | 7.5 | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are … | Sep 23, 2026 |
| CVE-2026-91776 | HIGH | 7.5 | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use … | Sep 23, 2026 |
| CVE-2026-89425 | HIGH | 7.5 | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has … | Sep 23, 2026 |
| CVE-2026-95928 | MEDIUM | 5.5 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict … | Sep 23, 2026 |
| CVE-2026-95927 | HIGH | 7.3 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument … | Sep 23, 2026 |
| CVE-2026-95926 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of … | Sep 23, 2026 |
| CVE-2026-96273 | MEDIUM | 5.5 | Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious … | Sep 23, 2026 |
| CVE-2026-96272 | HIGH | 7.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE … | Sep 23, 2026 |
| CVE-2026-96271 | HIGH | 7.1 | Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by … | Sep 23, 2026 |
| CVE-2026-95925 | HIGH | 7.3 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of … | Sep 23, 2026 |