Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101890 | MEDIUM | 5.4 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped … | Oct 01, 2026 |
| CVE-2026-101889 | MEDIUM | 6.5 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted … | Oct 01, 2026 |
| CVE-2026-101888 | HIGH | 7.2 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the … | Oct 01, 2026 |
| CVE-2025-31980 | MEDIUM | 4.3 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, … | Oct 01, 2026 |
| CVE-2026-9864 | MEDIUM | 4.8 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations … | Oct 01, 2026 |
| CVE-2026-94620 | UNKNOWN | — | Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each … | Oct 01, 2026 |
| CVE-2026-79896 | HIGH | 7.5 | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed … | Oct 01, 2026 |
| CVE-2026-47360 | HIGH | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may … | Oct 01, 2026 |
| CVE-2026-46729 | HIGH | 7.5 | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-42528 | MEDIUM | 4.3 | A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child … | Oct 01, 2026 |
| CVE-2026-42356 | LOW | 3.7 | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI … | Oct 01, 2026 |
| CVE-2026-18734 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Oct 01, 2026 |
| CVE-2026-17053 | MEDIUM | 4.4 | The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded … | Oct 01, 2026 |
| CVE-2026-12627 | CRITICAL | 9.8 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may … | Oct 01, 2026 |
| CVE-2026-103690 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the … | Oct 01, 2026 |
| CVE-2026-103505 | MEDIUM | 6.5 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with … | Oct 01, 2026 |
| CVE-2026-101322 | UNKNOWN | — | In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests … | Oct 01, 2026 |
| CVE-2026-97297 | HIGH | 7.6 | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | Oct 01, 2026 |
| CVE-2026-97284 | HIGH | 8.8 | Contributor PHP Object Injection in Icegram <= 3.1.31 versions. | Oct 01, 2026 |
| CVE-2026-97281 | MEDIUM | 6.3 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | Oct 01, 2026 |
| CVE-2026-97280 | MEDIUM | 6.5 | Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | Oct 01, 2026 |
| CVE-2026-97277 | HIGH | 7.6 | Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | Oct 01, 2026 |
| CVE-2026-97273 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | Oct 01, 2026 |
| CVE-2026-97269 | MEDIUM | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | Oct 01, 2026 |
| CVE-2026-97268 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | Oct 01, 2026 |