Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-75157 UNKNOWN — Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could … Sep 18, 2026
CVE-2026-67103 HIGH 7.6 HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a … Sep 18, 2026
CVE-2026-67102 HIGH 8.1 HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative … Sep 18, 2026
CVE-2026-67101 CRITICAL 9.3 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the … Sep 18, 2026
CVE-2026-67100 CRITICAL 9.8 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject … Sep 18, 2026
CVE-2026-18442 HIGH 7.5 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up … Sep 18, 2026
CVE-2026-17607 MEDIUM 6.5 The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, … Sep 18, 2026
CVE-2026-17586 MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, … Sep 18, 2026
CVE-2026-16777 MEDIUM 4.9 The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … Sep 18, 2026
CVE-2026-15275 HIGH 7.5 The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and … Sep 18, 2026
CVE-2026-15004 MEDIUM 5.4 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all … Sep 18, 2026
CVE-2026-14472 MEDIUM 6.4 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, … Sep 18, 2026
CVE-2026-14323 HIGH 7.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 … Sep 18, 2026
CVE-2026-13471 MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … Sep 18, 2026
CVE-2026-12954 HIGH 8.8 The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` … Sep 18, 2026
CVE-2026-12739 MEDIUM 4.3 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Sep 18, 2026
CVE-2026-12384 HIGH 8.8 Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor … Sep 18, 2026
CVE-2026-11757 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue … Sep 18, 2026
CVE-2026-92714 MEDIUM 6.5 The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked … Sep 18, 2026
CVE-2026-92619 HIGH 7.2 The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The … Sep 18, 2026
CVE-2026-92561 MEDIUM 6.1 The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due … Sep 18, 2026
CVE-2026-91707 MEDIUM 5.3 The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the … Sep 18, 2026
CVE-2026-90977 MEDIUM 5.3 The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass … Sep 18, 2026
CVE-2026-90976 MEDIUM 5.3 The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated … Sep 18, 2026
CVE-2026-89413 HIGH 8.1 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin … Sep 18, 2026