Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-93952 CRITICAL 10.0 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … Sep 22, 2026
CVE-2026-93836 HIGH 7.2 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and … Sep 22, 2026
CVE-2026-93778 HIGH 7.2 The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up … Sep 22, 2026
CVE-2026-92969 HIGH 8.1 The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 … Sep 22, 2026
CVE-2026-92235 HIGH 8.1 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due … Sep 22, 2026
CVE-2026-91092 MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin … Sep 22, 2026
CVE-2026-87082 HIGH 7.5 Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input … Sep 22, 2026
CVE-2026-87081 HIGH 7.5 Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode … Sep 22, 2026
CVE-2026-87080 CRITICAL 9.1 Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads … Sep 22, 2026
CVE-2026-87079 HIGH 7.5 Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each … Sep 22, 2026
CVE-2026-87078 CRITICAL 9.1 Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it … Sep 22, 2026
CVE-2026-7622 MEDIUM 4.3 The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and … Sep 22, 2026
CVE-2026-74766 HIGH 8.4 Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The … Sep 22, 2026
CVE-2026-74765 MEDIUM 6.5 Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode … Sep 22, 2026
CVE-2026-6922 HIGH 7.1 The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, … Sep 22, 2026
CVE-2026-4123 MEDIUM 4.3 The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to … Sep 22, 2026
CVE-2026-1645 MEDIUM 4.4 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and … Sep 22, 2026
CVE-2026-18439 MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … Sep 22, 2026
CVE-2026-18345 MEDIUM 4.3 The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in … Sep 22, 2026
CVE-2026-16778 MEDIUM 6.4 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up … Sep 22, 2026
CVE-2026-12995 MEDIUM 4.3 The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value … Sep 22, 2026
CVE-2025-1281 HIGH 8.8 The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions … Sep 22, 2026
CVE-2025-1280 MEDIUM 6.5 The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes … Sep 22, 2026
CVE-2025-14487 MEDIUM 5.3 The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. … Sep 22, 2026
CVE-2025-14486 MEDIUM 5.3 The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. … Sep 22, 2026