Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-87909 HIGH 7.5 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to … Sep 19, 2026
CVE-2026-84434 CRITICAL 9.8 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This … Sep 19, 2026
CVE-2026-15760 MEDIUM 6.5 The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX … Sep 19, 2026
CVE-2026-15660 MEDIUM 4.3 The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability … Sep 19, 2026
CVE-2026-13354 HIGH 7.2 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, … Sep 19, 2026
CVE-2026-12042 MEDIUM 4.4 The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due … Sep 19, 2026
CVE-2026-77820 MEDIUM 6.4 The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to … Sep 19, 2026
CVE-2026-93923 HIGH 8.8 SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks … Sep 19, 2026
CVE-2026-93922 HIGH 8.8 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. … Sep 19, 2026
CVE-2026-93921 MEDIUM 4.3 SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call … Sep 19, 2026
CVE-2026-77875 UNKNOWN — The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can … Sep 19, 2026
CVE-2026-93740 CRITICAL 10.0 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to … Sep 18, 2026
CVE-2026-93739 CRITICAL 9.9 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can … Sep 18, 2026
CVE-2026-75885 CRITICAL 9.3 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. … Sep 18, 2026
CVE-2026-93894 UNKNOWN — In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used … Sep 18, 2026
CVE-2026-93738 CRITICAL 9.9 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results … Sep 18, 2026
CVE-2026-93574 MEDIUM 6.5 A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes … Sep 18, 2026
CVE-2026-93562 MEDIUM 6.5 A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending … Sep 18, 2026
CVE-2026-88097 HIGH 8.1 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. Sep 18, 2026
CVE-2026-85272 MEDIUM 4.3 Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate … Sep 18, 2026
CVE-2026-85271 MEDIUM 6.1 Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py … Sep 18, 2026
CVE-2026-71855 MEDIUM 5.9 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 … Sep 18, 2026
CVE-2026-71418 HIGH 7.5 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously … Sep 18, 2026
CVE-2026-68928 HIGH 8.6 Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a … Sep 18, 2026
CVE-2026-63452 HIGH 7.5 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work … Sep 18, 2026