Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84902 | MEDIUM | 6.8 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users … | Sep 18, 2026 |
| CVE-2026-84738 | CRITICAL | 9.1 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a … | Sep 18, 2026 |
| CVE-2026-81810 | HIGH | 7.2 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only … | Sep 18, 2026 |
| CVE-2026-81340 | LOW | 3.8 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing … | Sep 18, 2026 |
| CVE-2026-18912 | HIGH | 7.7 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the … | Sep 18, 2026 |
| CVE-2026-18911 | HIGH | 7.5 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. | Sep 18, 2026 |
| CVE-2026-17086 | HIGH | 8.8 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … | Sep 18, 2026 |
| CVE-2026-93468 | HIGH | 7.5 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files. | Sep 18, 2026 |
| CVE-2026-93467 | CRITICAL | 9.8 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized … | Sep 18, 2026 |
| CVE-2026-93371 | HIGH | 8.3 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of … | Sep 18, 2026 |
| CVE-2026-92991 | MEDIUM | 5.4 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This … | Sep 18, 2026 |
| CVE-2026-15650 | MEDIUM | 6.4 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute … | Sep 18, 2026 |
| CVE-2026-14855 | MEDIUM | 6.4 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 … | Sep 18, 2026 |
| CVE-2026-93456 | HIGH | 8.2 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting … | Sep 18, 2026 |
| CVE-2026-93455 | MEDIUM | 6.5 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media … | Sep 18, 2026 |
| CVE-2026-93331 | HIGH | 7.3 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of … | Sep 18, 2026 |
| CVE-2026-93314 | MEDIUM | 6.3 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can … | Sep 18, 2026 |
| CVE-2026-93313 | MEDIUM | 6.3 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer … | Sep 18, 2026 |
| CVE-2026-82985 | MEDIUM | 6.5 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album … | Sep 18, 2026 |
| CVE-2026-82982 | MEDIUM | 4.3 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a … | Sep 18, 2026 |
| CVE-2026-82980 | MEDIUM | 6.3 | Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files … | Sep 18, 2026 |
| CVE-2026-77170 | MEDIUM | 4.3 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission … | Sep 18, 2026 |
| CVE-2026-77169 | MEDIUM | 6.5 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level … | Sep 18, 2026 |
| CVE-2026-77164 | MEDIUM | 6.2 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, … | Sep 18, 2026 |
| CVE-2026-68493 | LOW | 3.1 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are … | Sep 18, 2026 |