Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-14484 | MEDIUM | 5.3 | The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, … | Sep 22, 2026 |
| CVE-2016-15059 | CRITICAL | 9.8 | Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the … | Sep 22, 2026 |
| CVE-2026-94504 | HIGH | 7.2 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break … | Sep 22, 2026 |
| CVE-2026-92438 | HIGH | 8.8 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, … | Sep 22, 2026 |
| CVE-2026-91827 | HIGH | 7.5 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, … | Sep 22, 2026 |
| CVE-2026-89412 | HIGH | 7.2 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on … | Sep 22, 2026 |
| CVE-2026-93655 | MEDIUM | 6.1 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due … | Sep 22, 2026 |
| CVE-2026-88788 | MEDIUM | 6.8 | The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does … | Sep 22, 2026 |
| CVE-2026-85653 | MEDIUM | 6.4 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 … | Sep 22, 2026 |
| CVE-2026-12470 | HIGH | 7.2 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … | Sep 22, 2026 |
| CVE-2026-19658 | CRITICAL | 9.8 | The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input … | Sep 22, 2026 |
| CVE-2026-13355 | CRITICAL | 9.8 | The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to … | Sep 22, 2026 |
| CVE-2026-94493 | CRITICAL | 10.0 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation … | Sep 22, 2026 |
| CVE-2026-94492 | MEDIUM | 6.3 | A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation … | Sep 22, 2026 |
| CVE-2026-94491 | HIGH | 7.3 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address … | Sep 22, 2026 |
| CVE-2026-93712 | HIGH | 7.5 | Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins … | Sep 22, 2026 |
| CVE-2026-93711 | MEDIUM | 6.5 | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from … | Sep 22, 2026 |
| CVE-2026-93710 | HIGH | 7.5 | Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. … | Sep 22, 2026 |
| CVE-2026-93709 | UNKNOWN | — | Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage … | Sep 22, 2026 |
| CVE-2026-76974 | MEDIUM | 5.3 | SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, … | Sep 22, 2026 |
| CVE-2026-94490 | MEDIUM | 4.7 | A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command … | Sep 22, 2026 |
| CVE-2026-94489 | MEDIUM | 4.3 | A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. … | Sep 22, 2026 |
| CVE-2026-94426 | LOW | 3.5 | A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the … | Sep 21, 2026 |
| CVE-2026-94425 | HIGH | 8.8 | A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the … | Sep 21, 2026 |
| CVE-2026-94627 | HIGH | 7.5 | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode … | Sep 21, 2026 |