Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93952 | CRITICAL | 10.0 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … | Sep 22, 2026 |
| CVE-2026-93836 | HIGH | 7.2 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and … | Sep 22, 2026 |
| CVE-2026-93778 | HIGH | 7.2 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up … | Sep 22, 2026 |
| CVE-2026-92969 | HIGH | 8.1 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 … | Sep 22, 2026 |
| CVE-2026-92235 | HIGH | 8.1 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due … | Sep 22, 2026 |
| CVE-2026-91092 | MEDIUM | 4.3 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin … | Sep 22, 2026 |
| CVE-2026-87082 | HIGH | 7.5 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input … | Sep 22, 2026 |
| CVE-2026-87081 | HIGH | 7.5 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode … | Sep 22, 2026 |
| CVE-2026-87080 | CRITICAL | 9.1 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads … | Sep 22, 2026 |
| CVE-2026-87079 | HIGH | 7.5 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each … | Sep 22, 2026 |
| CVE-2026-87078 | CRITICAL | 9.1 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it … | Sep 22, 2026 |
| CVE-2026-7622 | MEDIUM | 4.3 | The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and … | Sep 22, 2026 |
| CVE-2026-74766 | HIGH | 8.4 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The … | Sep 22, 2026 |
| CVE-2026-74765 | MEDIUM | 6.5 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode … | Sep 22, 2026 |
| CVE-2026-6922 | HIGH | 7.1 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, … | Sep 22, 2026 |
| CVE-2026-4123 | MEDIUM | 4.3 | The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to … | Sep 22, 2026 |
| CVE-2026-1645 | MEDIUM | 4.4 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and … | Sep 22, 2026 |
| CVE-2026-18439 | MEDIUM | 4.3 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … | Sep 22, 2026 |
| CVE-2026-18345 | MEDIUM | 4.3 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in … | Sep 22, 2026 |
| CVE-2026-16778 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up … | Sep 22, 2026 |
| CVE-2026-12995 | MEDIUM | 4.3 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value … | Sep 22, 2026 |
| CVE-2025-1281 | HIGH | 8.8 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions … | Sep 22, 2026 |
| CVE-2025-1280 | MEDIUM | 6.5 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes … | Sep 22, 2026 |
| CVE-2025-14487 | MEDIUM | 5.3 | The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. … | Sep 22, 2026 |
| CVE-2025-14486 | MEDIUM | 5.3 | The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. … | Sep 22, 2026 |