Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2026-84902 MEDIUM 6.8 The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users … Sep 18, 2026
CVE-2026-84738 CRITICAL 9.1 The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a … Sep 18, 2026
CVE-2026-81810 HIGH 7.2 The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only … Sep 18, 2026
CVE-2026-81340 LOW 3.8 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing … Sep 18, 2026
CVE-2026-18912 HIGH 7.7 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the … Sep 18, 2026
CVE-2026-18911 HIGH 7.5 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. Sep 18, 2026
CVE-2026-17086 HIGH 8.8 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … Sep 18, 2026
CVE-2026-93468 HIGH 7.5 The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files. Sep 18, 2026
CVE-2026-93467 CRITICAL 9.8 The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized … Sep 18, 2026
CVE-2026-93371 HIGH 8.3 A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of … Sep 18, 2026
CVE-2026-92991 MEDIUM 5.4 The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This … Sep 18, 2026
CVE-2026-15650 MEDIUM 6.4 The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute … Sep 18, 2026
CVE-2026-14855 MEDIUM 6.4 The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 … Sep 18, 2026
CVE-2026-93456 HIGH 8.2 django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting … Sep 18, 2026
CVE-2026-93455 MEDIUM 6.5 django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media … Sep 18, 2026
CVE-2026-93331 HIGH 7.3 A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of … Sep 18, 2026
CVE-2026-93314 MEDIUM 6.3 A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can … Sep 18, 2026
CVE-2026-93313 MEDIUM 6.3 A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer … Sep 18, 2026
CVE-2026-82985 MEDIUM 6.5 The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album … Sep 18, 2026
CVE-2026-82982 MEDIUM 4.3 The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a … Sep 18, 2026
CVE-2026-82980 MEDIUM 6.3 Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files … Sep 18, 2026
CVE-2026-77170 MEDIUM 4.3 The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission … Sep 18, 2026
CVE-2026-77169 MEDIUM 6.5 A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level … Sep 18, 2026
CVE-2026-77164 MEDIUM 6.2 Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, … Sep 18, 2026
CVE-2026-68493 LOW 3.1 After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are … Sep 18, 2026