Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87840 | MEDIUM | 5.3 | The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated … | Sep 20, 2026 |
| CVE-2026-87839 | HIGH | 7.5 | The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX … | Sep 20, 2026 |
| CVE-2026-87068 | MEDIUM | 6.6 | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported … | Sep 20, 2026 |
| CVE-2026-87067 | HIGH | 8.5 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, … | Sep 20, 2026 |
| CVE-2026-85017 | HIGH | 7.5 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through … | Sep 20, 2026 |
| CVE-2026-84223 | MEDIUM | 6.8 | The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to … | Sep 20, 2026 |
| CVE-2026-82842 | HIGH | 8.1 | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress … | Sep 20, 2026 |
| CVE-2026-81654 | LOW | 3.1 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, … | Sep 20, 2026 |
| CVE-2026-81653 | MEDIUM | 4.2 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs … | Sep 20, 2026 |
| CVE-2026-81652 | LOW | 2.7 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before … | Sep 20, 2026 |
| CVE-2026-81651 | LOW | 3.1 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted … | Sep 20, 2026 |
| CVE-2026-81650 | HIGH | 7.2 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to … | Sep 20, 2026 |
| CVE-2026-16542 | MEDIUM | 4.1 | The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, … | Sep 20, 2026 |
| CVE-2026-14844 | MEDIUM | 6.8 | The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, … | Sep 20, 2026 |
| CVE-2026-93965 | MEDIUM | 6.6 | A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. … | Sep 20, 2026 |
| CVE-2026-93964 | MEDIUM | 5.3 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The … | Sep 20, 2026 |
| CVE-2026-93963 | MEDIUM | 6.3 | A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the … | Sep 20, 2026 |
| CVE-2026-93962 | HIGH | 8.3 | A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP … | Sep 20, 2026 |
| CVE-2026-93961 | MEDIUM | 5.3 | A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the … | Sep 20, 2026 |
| CVE-2026-93960 | MEDIUM | 4.3 | A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such … | Sep 20, 2026 |
| CVE-2026-86553 | HIGH | 8.8 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call … | Sep 20, 2026 |
| CVE-2026-86552 | MEDIUM | 5.4 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using … | Sep 20, 2026 |
| CVE-2026-93959 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the … | Sep 20, 2026 |
| CVE-2026-94084 | CRITICAL | 9.4 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. | Sep 20, 2026 |
| CVE-2026-94083 | CRITICAL | 9.4 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though … | Sep 20, 2026 |