Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-81637 UNKNOWN — Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim … Sep 17, 2026
CVE-2026-81632 UNKNOWN — Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to … Sep 17, 2026
CVE-2026-81453 MEDIUM 6.5 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged … Sep 17, 2026
CVE-2026-81443 MEDIUM 6.4 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit … Sep 17, 2026
CVE-2026-81442 HIGH 8.1 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this … Sep 17, 2026
CVE-2026-80355 MEDIUM 5.4 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this … Sep 17, 2026
CVE-2026-80218 UNKNOWN — Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of … Sep 17, 2026
CVE-2026-78528 MEDIUM 5.3 Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. Sep 17, 2026
CVE-2026-78295 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. Sep 17, 2026
CVE-2026-78294 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. Sep 17, 2026
CVE-2026-78223 UNKNOWN — Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows … Sep 17, 2026
CVE-2026-74017 MEDIUM 5.3 Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. Sep 17, 2026
CVE-2026-74005 MEDIUM 5.4 Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. Sep 17, 2026
CVE-2026-74002 MEDIUM 5.3 Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. Sep 17, 2026
CVE-2026-74000 MEDIUM 5.3 Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. Sep 17, 2026
CVE-2026-73999 MEDIUM 5.4 Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. Sep 17, 2026
CVE-2026-71568 MEDIUM 5.3 In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, … Sep 17, 2026
CVE-2026-66676 MEDIUM 5.3 Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. Sep 17, 2026
CVE-2026-66631 HIGH 7.6 Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. Sep 17, 2026
CVE-2026-66630 HIGH 7.6 Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. Sep 17, 2026
CVE-2026-66628 HIGH 7.6 Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. Sep 17, 2026
CVE-2026-66626 HIGH 7.6 Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. Sep 17, 2026
CVE-2026-66625 HIGH 7.6 Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. Sep 17, 2026
CVE-2026-66624 HIGH 7.6 Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. Sep 17, 2026
CVE-2026-66619 HIGH 7.6 Administrator SQL Injection in Newsletters <= 4.18 versions. Sep 17, 2026