Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-92244 HIGH 7.2 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / … Oct 01, 2026
CVE-2026-90992 MEDIUM 6.4 The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, … Oct 01, 2026
CVE-2026-89427 MEDIUM 6.1 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions … Oct 01, 2026
CVE-2026-89424 MEDIUM 6.4 The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due … Oct 01, 2026
CVE-2026-85235 HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field … Oct 01, 2026
CVE-2026-15983 HIGH 8.1 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, … Oct 01, 2026
CVE-2026-14995 HIGH 7.2 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient … Oct 01, 2026
CVE-2026-103664 UNKNOWN — MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, … Oct 01, 2026
CVE-2026-103662 UNKNOWN — MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed … Oct 01, 2026
CVE-2026-103659 UNKNOWN — MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the … Oct 01, 2026
CVE-2026-103656 UNKNOWN — Rejected reason: this is rejected Oct 01, 2026
CVE-2026-103655 UNKNOWN — MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its … Oct 01, 2026
CVE-2026-103431 HIGH 7.7 colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local … Oct 01, 2026
CVE-2026-101925 MEDIUM 6.4 The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter … Oct 01, 2026
CVE-2026-100184 MEDIUM 4.7 The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based … Oct 01, 2026
CVE-2026-100179 MEDIUM 6.1 The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based … Oct 01, 2026
CVE-2026-93882 HIGH 7.5 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … Oct 01, 2026
CVE-2026-89047 MEDIUM 6.1 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, … Oct 01, 2026
CVE-2026-78249 UNKNOWN — A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, … Oct 01, 2026
CVE-2026-75957 CRITICAL 9.8 The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … Oct 01, 2026
CVE-2026-19902 MEDIUM 6.1 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions … Oct 01, 2026
CVE-2026-19807 HIGH 8.8 The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This … Oct 01, 2026
CVE-2026-15989 CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … Oct 01, 2026
CVE-2026-103651 UNKNOWN — MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token … Oct 01, 2026
CVE-2026-103544 MEDIUM 6.3 A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al … Oct 01, 2026