Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-25265 | HIGH | 8.8 | Privilege escalation due to weak configuration while temporary file handling. | Sep 22, 2026 |
| CVE-2026-25264 | HIGH | 8.8 | Privilege escalation due to weak configuration during package extraction process. | Sep 22, 2026 |
| CVE-2026-25262 | MEDIUM | 6.9 | Memory corruption while processing a crafted ELF file in the Primary Bootloader. | Sep 22, 2026 |
| CVE-2026-25255 | HIGH | 8.8 | Exposed dangerous function lead to privilege escalation via gRPC server. | Sep 22, 2026 |
| CVE-2026-25254 | CRITICAL | 9.8 | Improper authorization leads to Remote Code Execution via SocketIO interface. | Sep 22, 2026 |
| CVE-2026-9231 | HIGH | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up … | Sep 22, 2026 |
| CVE-2026-95511 | UNKNOWN | — | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted … | Sep 22, 2026 |
| CVE-2026-95508 | HIGH | 7.4 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, … | Sep 22, 2026 |
| CVE-2026-93928 | HIGH | 7.3 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking … | Sep 22, 2026 |
| CVE-2026-93556 | UNKNOWN | — | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is … | Sep 22, 2026 |
| CVE-2026-89422 | UNKNOWN | — | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A … | Sep 22, 2026 |
| CVE-2026-68956 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels … | Sep 22, 2026 |
| CVE-2026-65634 | UNKNOWN | — | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID … | Sep 22, 2026 |
| CVE-2026-15095 | MEDIUM | 4.9 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in … | Sep 22, 2026 |
| CVE-2026-9004 | MEDIUM | 4.3 | The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 … | Sep 22, 2026 |
| CVE-2026-95503 | MEDIUM | 6.8 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without … | Sep 22, 2026 |
| CVE-2026-93952 | CRITICAL | 10.0 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … | Sep 22, 2026 |
| CVE-2026-93836 | HIGH | 7.2 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and … | Sep 22, 2026 |
| CVE-2026-93778 | HIGH | 7.2 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up … | Sep 22, 2026 |
| CVE-2026-92969 | HIGH | 8.1 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 … | Sep 22, 2026 |
| CVE-2026-92235 | HIGH | 8.1 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due … | Sep 22, 2026 |
| CVE-2026-91092 | MEDIUM | 4.3 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin … | Sep 22, 2026 |
| CVE-2026-87082 | HIGH | 7.5 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input … | Sep 22, 2026 |
| CVE-2026-87081 | HIGH | 7.5 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode … | Sep 22, 2026 |
| CVE-2026-87080 | CRITICAL | 9.1 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads … | Sep 22, 2026 |