Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87909 | HIGH | 7.5 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to … | Sep 19, 2026 |
| CVE-2026-84434 | CRITICAL | 9.8 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This … | Sep 19, 2026 |
| CVE-2026-15760 | MEDIUM | 6.5 | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX … | Sep 19, 2026 |
| CVE-2026-15660 | MEDIUM | 4.3 | The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability … | Sep 19, 2026 |
| CVE-2026-13354 | HIGH | 7.2 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-12042 | MEDIUM | 4.4 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due … | Sep 19, 2026 |
| CVE-2026-77820 | MEDIUM | 6.4 | The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to … | Sep 19, 2026 |
| CVE-2026-93923 | HIGH | 8.8 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks … | Sep 19, 2026 |
| CVE-2026-93922 | HIGH | 8.8 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. … | Sep 19, 2026 |
| CVE-2026-93921 | MEDIUM | 4.3 | SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call … | Sep 19, 2026 |
| CVE-2026-77875 | UNKNOWN | — | The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can … | Sep 19, 2026 |
| CVE-2026-93740 | CRITICAL | 10.0 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to … | Sep 18, 2026 |
| CVE-2026-93739 | CRITICAL | 9.9 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can … | Sep 18, 2026 |
| CVE-2026-75885 | CRITICAL | 9.3 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. … | Sep 18, 2026 |
| CVE-2026-93894 | UNKNOWN | — | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used … | Sep 18, 2026 |
| CVE-2026-93738 | CRITICAL | 9.9 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results … | Sep 18, 2026 |
| CVE-2026-93574 | MEDIUM | 6.5 | A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes … | Sep 18, 2026 |
| CVE-2026-93562 | MEDIUM | 6.5 | A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending … | Sep 18, 2026 |
| CVE-2026-88097 | HIGH | 8.1 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. | Sep 18, 2026 |
| CVE-2026-85272 | MEDIUM | 4.3 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate … | Sep 18, 2026 |
| CVE-2026-85271 | MEDIUM | 6.1 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py … | Sep 18, 2026 |
| CVE-2026-71855 | MEDIUM | 5.9 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 … | Sep 18, 2026 |
| CVE-2026-71418 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously … | Sep 18, 2026 |
| CVE-2026-68928 | HIGH | 8.6 | Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a … | Sep 18, 2026 |
| CVE-2026-63452 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work … | Sep 18, 2026 |