Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-101890 MEDIUM 5.4 The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped … Oct 01, 2026
CVE-2026-101889 MEDIUM 6.5 The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted … Oct 01, 2026
CVE-2026-101888 HIGH 7.2 The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the … Oct 01, 2026
CVE-2025-31980 MEDIUM 4.3 HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, … Oct 01, 2026
CVE-2026-9864 MEDIUM 4.8 Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations … Oct 01, 2026
CVE-2026-94620 UNKNOWN — Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each … Oct 01, 2026
CVE-2026-79896 HIGH 7.5 Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed … Oct 01, 2026
CVE-2026-47360 HIGH 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may … Oct 01, 2026
CVE-2026-46729 HIGH 7.5 NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. Oct 01, 2026
CVE-2026-42528 MEDIUM 4.3 A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child … Oct 01, 2026
CVE-2026-42356 LOW 3.7 Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI … Oct 01, 2026
CVE-2026-18734 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Oct 01, 2026
CVE-2026-17053 MEDIUM 4.4 The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded … Oct 01, 2026
CVE-2026-12627 CRITICAL 9.8 Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may … Oct 01, 2026
CVE-2026-103690 MEDIUM 6.3 A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the … Oct 01, 2026
CVE-2026-103505 MEDIUM 6.5 Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with … Oct 01, 2026
CVE-2026-101322 UNKNOWN — In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests … Oct 01, 2026
CVE-2026-97297 HIGH 7.6 Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. Oct 01, 2026
CVE-2026-97284 HIGH 8.8 Contributor PHP Object Injection in Icegram <= 3.1.31 versions. Oct 01, 2026
CVE-2026-97281 MEDIUM 6.3 Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. Oct 01, 2026
CVE-2026-97280 MEDIUM 6.5 Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. Oct 01, 2026
CVE-2026-97277 HIGH 7.6 Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. Oct 01, 2026
CVE-2026-97273 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. Oct 01, 2026
CVE-2026-97269 MEDIUM 6.5 Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. Oct 01, 2026
CVE-2026-97268 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. Oct 01, 2026