Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81637 | UNKNOWN | — | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim … | Sep 17, 2026 |
| CVE-2026-81632 | UNKNOWN | — | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to … | Sep 17, 2026 |
| CVE-2026-81453 | MEDIUM | 6.5 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged … | Sep 17, 2026 |
| CVE-2026-81443 | MEDIUM | 6.4 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-81442 | HIGH | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-80355 | MEDIUM | 5.4 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-80218 | UNKNOWN | — | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of … | Sep 17, 2026 |
| CVE-2026-78528 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | Sep 17, 2026 |
| CVE-2026-78295 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. | Sep 17, 2026 |
| CVE-2026-78294 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | Sep 17, 2026 |
| CVE-2026-78223 | UNKNOWN | — | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows … | Sep 17, 2026 |
| CVE-2026-74017 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. | Sep 17, 2026 |
| CVE-2026-74005 | MEDIUM | 5.4 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | Sep 17, 2026 |
| CVE-2026-74002 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. | Sep 17, 2026 |
| CVE-2026-74000 | MEDIUM | 5.3 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | Sep 17, 2026 |
| CVE-2026-73999 | MEDIUM | 5.4 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | Sep 17, 2026 |
| CVE-2026-71568 | MEDIUM | 5.3 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, … | Sep 17, 2026 |
| CVE-2026-66676 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | Sep 17, 2026 |
| CVE-2026-66631 | HIGH | 7.6 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | Sep 17, 2026 |
| CVE-2026-66630 | HIGH | 7.6 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | Sep 17, 2026 |
| CVE-2026-66628 | HIGH | 7.6 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | Sep 17, 2026 |
| CVE-2026-66626 | HIGH | 7.6 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | Sep 17, 2026 |
| CVE-2026-66625 | HIGH | 7.6 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | Sep 17, 2026 |
| CVE-2026-66624 | HIGH | 7.6 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | Sep 17, 2026 |
| CVE-2026-66619 | HIGH | 7.6 | Administrator SQL Injection in Newsletters <= 4.18 versions. | Sep 17, 2026 |