Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-41753 | CRITICAL | 9.8 | The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited … | Oct 01, 2026 |
| CVE-2026-96255 | HIGH | 7.5 | The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the … | Oct 01, 2026 |
| CVE-2026-96200 | MEDIUM | 5.3 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing … | Oct 01, 2026 |
| CVE-2026-96173 | MEDIUM | 5.3 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback … | Oct 01, 2026 |
| CVE-2026-92412 | HIGH | 7.1 | The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated … | Oct 01, 2026 |
| CVE-2026-90974 | MEDIUM | 6.5 | The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to … | Oct 01, 2026 |
| CVE-2026-90972 | MEDIUM | 5.4 | The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber … | Oct 01, 2026 |
| CVE-2026-89296 | HIGH | 8.6 | The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated … | Oct 01, 2026 |
| CVE-2026-88999 | MEDIUM | 4.3 | The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin … | Oct 01, 2026 |
| CVE-2026-87973 | LOW | 3.1 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, … | Oct 01, 2026 |
| CVE-2026-87970 | MEDIUM | 4.7 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served … | Oct 01, 2026 |
| CVE-2026-86610 | MEDIUM | 6.4 | The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could … | Oct 01, 2026 |
| CVE-2026-85679 | HIGH | 7.2 | The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due … | Oct 01, 2026 |
| CVE-2026-81809 | HIGH | 7.5 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and … | Oct 01, 2026 |
| CVE-2026-81739 | HIGH | 7.5 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin … | Oct 01, 2026 |
| CVE-2026-80276 | HIGH | 7.5 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this … | Oct 01, 2026 |
| CVE-2026-80275 | HIGH | 8.8 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated … | Oct 01, 2026 |
| CVE-2026-67075 | MEDIUM | 6.5 | HCL Digital Experience is affected by improper input sanitation. This can result in HTML injection which could be leveraged in content spoofing from a trusted … | Oct 01, 2026 |
| CVE-2026-19253 | HIGH | 8.7 | The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, … | Oct 01, 2026 |
| CVE-2026-103543 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of … | Oct 01, 2026 |
| CVE-2026-103542 | MEDIUM | 4.3 | A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX … | Oct 01, 2026 |
| CVE-2026-103541 | MEDIUM | 6.3 | A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax … | Oct 01, 2026 |
| CVE-2026-103540 | MEDIUM | 6.3 | A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the … | Oct 01, 2026 |
| CVE-2026-101148 | CRITICAL | 10.0 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which … | Oct 01, 2026 |
| CVE-2026-101147 | HIGH | 8.8 | The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the … | Oct 01, 2026 |