Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7174 | UNKNOWN | — | CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating … | Oct 01, 2026 |
| CVE-2026-7173 | UNKNOWN | — | CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the … | Oct 01, 2026 |
| CVE-2026-75786 | UNKNOWN | — | Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards. | Oct 01, 2026 |
| CVE-2026-64950 | UNKNOWN | — | Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora … | Oct 01, 2026 |
| CVE-2026-64949 | UNKNOWN | — | Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards. | Oct 01, 2026 |
| CVE-2026-64948 | UNKNOWN | — | Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards. | Oct 01, 2026 |
| CVE-2026-64947 | UNKNOWN | — | A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting … | Oct 01, 2026 |
| CVE-2026-64946 | UNKNOWN | — | A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account … | Oct 01, 2026 |
| CVE-2026-34190 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This … | Oct 01, 2026 |
| CVE-2026-34189 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This … | Oct 01, 2026 |
| CVE-2026-103497 | MEDIUM | 5.5 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | Oct 01, 2026 |
| CVE-2026-103496 | MEDIUM | 5.4 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | Oct 01, 2026 |
| CVE-2026-103495 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | Oct 01, 2026 |
| CVE-2026-103494 | MEDIUM | 6.6 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | Oct 01, 2026 |
| CVE-2026-103493 | HIGH | 8.1 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | Oct 01, 2026 |
| CVE-2026-103492 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | Oct 01, 2026 |
| CVE-2026-103491 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | Oct 01, 2026 |
| CVE-2026-103490 | HIGH | 7.2 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | Oct 01, 2026 |
| CVE-2026-103489 | LOW | 2.0 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | Oct 01, 2026 |
| CVE-2026-103488 | HIGH | 7.1 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | Oct 01, 2026 |
| CVE-2026-97661 | HIGH | 7.2 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, … | Oct 01, 2026 |
| CVE-2026-96813 | HIGH | 7.2 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on … | Oct 01, 2026 |
| CVE-2026-96573 | HIGH | 7.2 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar … | Oct 01, 2026 |
| CVE-2026-96268 | MEDIUM | 6.4 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions … | Oct 01, 2026 |
| CVE-2026-95687 | HIGH | 8.8 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … | Oct 01, 2026 |