Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

11537
Total
770
Critical
3263
High
3665
Medium
CVE ID Severity Score Description Published
CVE-2026-5847 MEDIUM 4.3 A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database … Apr 09, 2026
CVE-2026-5844 HIGH 7.2 A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation … Apr 09, 2026
CVE-2026-5842 HIGH 7.3 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the … Apr 09, 2026
CVE-2026-5841 HIGH 7.3 A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can … Apr 09, 2026
CVE-2026-5840 MEDIUM 4.7 A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of … Apr 09, 2026
CVE-2026-5839 MEDIUM 4.7 A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the file /admin/add-subcategory.php. Such manipulation of the argument … Apr 09, 2026
CVE-2026-5838 MEDIUM 4.7 A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername … Apr 09, 2026
CVE-2026-5742 MEDIUM 6.4 The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization … Apr 09, 2026
CVE-2026-4336 MEDIUM 6.4 The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This … Apr 09, 2026
CVE-2026-1830 CRITICAL 9.8 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient … Apr 09, 2026
CVE-2026-5837 HIGH 7.3 A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment … Apr 09, 2026
CVE-2026-5836 LOW 2.4 A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation … Apr 09, 2026
CVE-2026-5835 LOW 2.4 A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a … Apr 09, 2026
CVE-2026-5834 LOW 2.4 A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument … Apr 09, 2026
CVE-2026-5833 MEDIUM 5.3 A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the … Apr 09, 2026
CVE-2026-5357 MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and … Apr 09, 2026
CVE-2026-4429 MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in … Apr 09, 2026
CVE-2026-4124 MEDIUM 5.4 The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce … Apr 09, 2026
CVE-2026-3574 MEDIUM 4.4 The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font … Apr 09, 2026
CVE-2026-3568 MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to … Apr 09, 2026
CVE-2026-5832 HIGH 7.3 A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. … Apr 09, 2026
CVE-2026-5831 MEDIUM 6.3 A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. … Apr 09, 2026
CVE-2026-5830 HIGH 8.8 A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to … Apr 09, 2026
CVE-2026-5829 HIGH 7.3 A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of … Apr 09, 2026
CVE-2026-5828 HIGH 7.3 A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of … Apr 09, 2026