Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-92966 CRITICAL 9.1 The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions … Oct 01, 2026
CVE-2026-92548 MEDIUM 5.3 The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. … Oct 01, 2026
CVE-2026-82829 CRITICAL 9.8 Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or … Oct 01, 2026
CVE-2026-82828 HIGH 8.8 Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: … Oct 01, 2026
CVE-2026-82827 CRITICAL 9.8 Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to … Oct 01, 2026
CVE-2026-82826 HIGH 7.5 Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials … Oct 01, 2026
CVE-2026-82825 CRITICAL 9.8 Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially … Oct 01, 2026
CVE-2026-82824 CRITICAL 9.8 Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue … Oct 01, 2026
CVE-2026-78210 UNKNOWN — In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. Oct 01, 2026
CVE-2026-76147 UNKNOWN — A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker … Oct 01, 2026
CVE-2026-76146 UNKNOWN — An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary … Oct 01, 2026
CVE-2026-76145 UNKNOWN — An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS … Oct 01, 2026
CVE-2026-76144 UNKNOWN — An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file … Oct 01, 2026
CVE-2026-76143 UNKNOWN — A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. Oct 01, 2026
CVE-2026-76142 UNKNOWN — Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions Oct 01, 2026
CVE-2026-12241 MEDIUM 5.4 The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly … Oct 01, 2026
CVE-2026-103539 MEDIUM 5.4 A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a … Oct 01, 2026
CVE-2026-103538 MEDIUM 6.5 A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component … Oct 01, 2026
CVE-2026-103536 HIGH 7.3 A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. … Oct 01, 2026
CVE-2026-96561 HIGH 7.2 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … Oct 01, 2026
CVE-2026-92245 HIGH 7.5 The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. … Oct 01, 2026
CVE-2026-91109 MEDIUM 6.5 The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' … Oct 01, 2026
CVE-2026-103641 MEDIUM 5.5 A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than … Oct 01, 2026
CVE-2026-103534 MEDIUM 6.3 A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This … Oct 01, 2026
CVE-2026-92537 MEDIUM 5.3 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 … Oct 01, 2026