Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-25265 HIGH 8.8 Privilege escalation due to weak configuration while temporary file handling. Sep 22, 2026
CVE-2026-25264 HIGH 8.8 Privilege escalation due to weak configuration during package extraction process. Sep 22, 2026
CVE-2026-25262 MEDIUM 6.9 Memory corruption while processing a crafted ELF file in the Primary Bootloader. Sep 22, 2026
CVE-2026-25255 HIGH 8.8 Exposed dangerous function lead to privilege escalation via gRPC server. Sep 22, 2026
CVE-2026-25254 CRITICAL 9.8 Improper authorization leads to Remote Code Execution via SocketIO interface. Sep 22, 2026
CVE-2026-9231 HIGH 7.5 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up … Sep 22, 2026
CVE-2026-95511 UNKNOWN — Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted … Sep 22, 2026
CVE-2026-95508 HIGH 7.4 A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, … Sep 22, 2026
CVE-2026-93928 HIGH 7.3 Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking … Sep 22, 2026
CVE-2026-93556 UNKNOWN — The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is … Sep 22, 2026
CVE-2026-89422 UNKNOWN — Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A … Sep 22, 2026
CVE-2026-68956 UNKNOWN — Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels … Sep 22, 2026
CVE-2026-65634 UNKNOWN — Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID … Sep 22, 2026
CVE-2026-15095 MEDIUM 4.9 The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in … Sep 22, 2026
CVE-2026-9004 MEDIUM 4.3 The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 … Sep 22, 2026
CVE-2026-95503 MEDIUM 6.8 A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without … Sep 22, 2026
CVE-2026-93952 CRITICAL 10.0 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … Sep 22, 2026
CVE-2026-93836 HIGH 7.2 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and … Sep 22, 2026
CVE-2026-93778 HIGH 7.2 The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up … Sep 22, 2026
CVE-2026-92969 HIGH 8.1 The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 … Sep 22, 2026
CVE-2026-92235 HIGH 8.1 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due … Sep 22, 2026
CVE-2026-91092 MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin … Sep 22, 2026
CVE-2026-87082 HIGH 7.5 Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input … Sep 22, 2026
CVE-2026-87081 HIGH 7.5 Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode … Sep 22, 2026
CVE-2026-87080 CRITICAL 9.1 Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads … Sep 22, 2026