Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-97260 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. Oct 01, 2026
CVE-2026-97258 MEDIUM 6.5 Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. Oct 01, 2026
CVE-2026-97251 MEDIUM 6.5 Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. Oct 01, 2026
CVE-2026-95588 HIGH 8.6 Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. Oct 01, 2026
CVE-2026-95137 UNKNOWN — Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not … Oct 01, 2026
CVE-2026-94390 HIGH 7.2 Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. Oct 01, 2026
CVE-2026-79900 MEDIUM 6.5 boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name … Oct 01, 2026
CVE-2026-79899 HIGH 7.9 Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local … Oct 01, 2026
CVE-2026-79898 CRITICAL 9.1 Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP … Oct 01, 2026
CVE-2026-67106 MEDIUM 5.3 HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker … Oct 01, 2026
CVE-2026-67105 HIGH 7.4 HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic … Oct 01, 2026
CVE-2026-67104 MEDIUM 5.3 HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the … Oct 01, 2026
CVE-2026-62073 HIGH 7.5 Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. Oct 01, 2026
CVE-2026-62071 CRITICAL 9.3 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. Oct 01, 2026
CVE-2026-56599 LOW 2.2 HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as … Oct 01, 2026
CVE-2026-56589 HIGH 7.2 HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within … Oct 01, 2026
CVE-2026-103752 CRITICAL 9.8 Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. Oct 01, 2026
CVE-2026-103687 HIGH 7.3 A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component … Oct 01, 2026
CVE-2026-103347 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. Oct 01, 2026
CVE-2026-103068 HIGH 8.8 Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions. Oct 01, 2026
CVE-2026-103004 UNKNOWN — Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With … Oct 01, 2026
CVE-2026-102378 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. Oct 01, 2026
CVE-2026-100517 HIGH 7.5 Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. Oct 01, 2026
CVE-2026-100514 HIGH 7.5 Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. Oct 01, 2026
CVE-2024-58388 HIGH 7.5 Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the … Oct 01, 2026