Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2025-13533 MEDIUM 4.4 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment … Sep 18, 2026
CVE-2026-93494 HIGH 7.5 A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its … Sep 18, 2026
CVE-2026-93493 MEDIUM 5.9 A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that … Sep 18, 2026
CVE-2026-92622 MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due … Sep 18, 2026
CVE-2026-92554 MEDIUM 6.1 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all … Sep 18, 2026
CVE-2026-92249 MEDIUM 6.1 The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, … Sep 18, 2026
CVE-2026-90981 MEDIUM 6.1 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up … Sep 18, 2026
CVE-2026-89059 HIGH 7.5 A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. … Sep 18, 2026
CVE-2026-89058 HIGH 7.4 A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response … Sep 18, 2026
CVE-2026-85705 HIGH 7.5 The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and … Sep 18, 2026
CVE-2026-85652 MEDIUM 6.5 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions … Sep 18, 2026
CVE-2026-75961 MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up … Sep 18, 2026
CVE-2026-75157 UNKNOWN — Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could … Sep 18, 2026
CVE-2026-67103 HIGH 7.6 HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a … Sep 18, 2026
CVE-2026-67102 HIGH 8.1 HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative … Sep 18, 2026
CVE-2026-67101 CRITICAL 9.3 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the … Sep 18, 2026
CVE-2026-67100 CRITICAL 9.8 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject … Sep 18, 2026
CVE-2026-18442 HIGH 7.5 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up … Sep 18, 2026
CVE-2026-17607 MEDIUM 6.5 The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, … Sep 18, 2026
CVE-2026-17586 MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, … Sep 18, 2026
CVE-2026-16777 MEDIUM 4.9 The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … Sep 18, 2026
CVE-2026-15275 HIGH 7.5 The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and … Sep 18, 2026
CVE-2026-15004 MEDIUM 5.4 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all … Sep 18, 2026
CVE-2026-14472 MEDIUM 6.4 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, … Sep 18, 2026
CVE-2026-14323 HIGH 7.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 … Sep 18, 2026