Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2024-38639 | MEDIUM | 4.8 | An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. … | Sep 18, 2026 |
| CVE-2024-27123 | UNKNOWN | — | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read … | Sep 18, 2026 |
| CVE-2026-93485 | HIGH | 7.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before … | Sep 18, 2026 |
| CVE-2026-90984 | MEDIUM | 5.8 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on … | Sep 18, 2026 |
| CVE-2026-90978 | HIGH | 7.1 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and … | Sep 18, 2026 |
| CVE-2026-89008 | LOW | 2.7 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users … | Sep 18, 2026 |
| CVE-2026-89007 | LOW | 2.7 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users … | Sep 18, 2026 |
| CVE-2026-88993 | MEDIUM | 6.8 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with … | Sep 18, 2026 |
| CVE-2026-88844 | LOW | 2.7 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing … | Sep 18, 2026 |
| CVE-2026-88825 | HIGH | 8.8 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts … | Sep 18, 2026 |
| CVE-2026-88798 | MEDIUM | 5.3 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of … | Sep 18, 2026 |
| CVE-2026-87966 | MEDIUM | 5.3 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment … | Sep 18, 2026 |
| CVE-2026-87965 | MEDIUM | 4.8 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token … | Sep 18, 2026 |
| CVE-2026-87775 | HIGH | 8.6 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on … | Sep 18, 2026 |
| CVE-2026-87774 | HIGH | 8.6 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on … | Sep 18, 2026 |
| CVE-2026-87771 | HIGH | 8.6 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available … | Sep 18, 2026 |
| CVE-2026-87770 | HIGH | 8.6 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on … | Sep 18, 2026 |
| CVE-2026-87767 | HIGH | 8.6 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query … | Sep 18, 2026 |
| CVE-2026-85350 | MEDIUM | 5.3 | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, … | Sep 18, 2026 |
| CVE-2026-85127 | HIGH | 8.8 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live … | Sep 18, 2026 |
| CVE-2026-85123 | MEDIUM | 5.3 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form … | Sep 18, 2026 |
| CVE-2026-85122 | HIGH | 8.8 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form … | Sep 18, 2026 |
| CVE-2026-85009 | MEDIUM | 6.5 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to … | Sep 18, 2026 |
| CVE-2026-84904 | LOW | 3.8 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on … | Sep 18, 2026 |
| CVE-2026-84903 | LOW | 2.7 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied … | Sep 18, 2026 |