Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92966 | CRITICAL | 9.1 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions … | Oct 01, 2026 |
| CVE-2026-92548 | MEDIUM | 5.3 | The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. … | Oct 01, 2026 |
| CVE-2026-82829 | CRITICAL | 9.8 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or … | Oct 01, 2026 |
| CVE-2026-82828 | HIGH | 8.8 | Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: … | Oct 01, 2026 |
| CVE-2026-82827 | CRITICAL | 9.8 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to … | Oct 01, 2026 |
| CVE-2026-82826 | HIGH | 7.5 | Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials … | Oct 01, 2026 |
| CVE-2026-82825 | CRITICAL | 9.8 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially … | Oct 01, 2026 |
| CVE-2026-82824 | CRITICAL | 9.8 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue … | Oct 01, 2026 |
| CVE-2026-78210 | UNKNOWN | — | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | Oct 01, 2026 |
| CVE-2026-76147 | UNKNOWN | — | A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker … | Oct 01, 2026 |
| CVE-2026-76146 | UNKNOWN | — | An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary … | Oct 01, 2026 |
| CVE-2026-76145 | UNKNOWN | — | An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS … | Oct 01, 2026 |
| CVE-2026-76144 | UNKNOWN | — | An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file … | Oct 01, 2026 |
| CVE-2026-76143 | UNKNOWN | — | A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | Oct 01, 2026 |
| CVE-2026-76142 | UNKNOWN | — | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | Oct 01, 2026 |
| CVE-2026-12241 | MEDIUM | 5.4 | The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly … | Oct 01, 2026 |
| CVE-2026-103539 | MEDIUM | 5.4 | A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a … | Oct 01, 2026 |
| CVE-2026-103538 | MEDIUM | 6.5 | A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component … | Oct 01, 2026 |
| CVE-2026-103536 | HIGH | 7.3 | A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. … | Oct 01, 2026 |
| CVE-2026-96561 | HIGH | 7.2 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | Oct 01, 2026 |
| CVE-2026-92245 | HIGH | 7.5 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. … | Oct 01, 2026 |
| CVE-2026-91109 | MEDIUM | 6.5 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' … | Oct 01, 2026 |
| CVE-2026-103641 | MEDIUM | 5.5 | A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than … | Oct 01, 2026 |
| CVE-2026-103534 | MEDIUM | 6.3 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This … | Oct 01, 2026 |
| CVE-2026-92537 | MEDIUM | 5.3 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 … | Oct 01, 2026 |