Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-66618 HIGH 7.6 Administrator SQL Injection in WP Maps <= 4.9.9 versions. Sep 17, 2026
CVE-2026-66617 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. Sep 17, 2026
CVE-2026-66608 MEDIUM 6.4 Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. Sep 17, 2026
CVE-2026-66580 HIGH 8.5 Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. Sep 17, 2026
CVE-2026-66579 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. Sep 17, 2026
CVE-2026-66578 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. Sep 17, 2026
CVE-2026-66577 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. Sep 17, 2026
CVE-2026-66576 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. Sep 17, 2026
CVE-2026-66575 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. Sep 17, 2026
CVE-2026-66574 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. Sep 17, 2026
CVE-2026-66573 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. Sep 17, 2026
CVE-2026-66572 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. Sep 17, 2026
CVE-2026-66571 HIGH 7.1 Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. Sep 17, 2026
CVE-2026-62108 CRITICAL 9.8 Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. Sep 17, 2026
CVE-2026-62104 CRITICAL 10.0 Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. Sep 17, 2026
CVE-2026-62101 CRITICAL 9.8 Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. Sep 17, 2026
CVE-2026-14850 UNKNOWN — The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric … Sep 17, 2026
CVE-2026-92932 UNKNOWN — In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original … Sep 17, 2026
CVE-2026-92921 MEDIUM 4.9 admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can … Sep 17, 2026
CVE-2026-92920 MEDIUM 5.4 admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue … Sep 17, 2026
CVE-2026-92919 HIGH 8.1 admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. … Sep 17, 2026
CVE-2026-92918 HIGH 8.8 admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the … Sep 17, 2026
CVE-2026-92904 MEDIUM 4.3 A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations … Sep 17, 2026
CVE-2026-81481 HIGH 7.5 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker … Sep 17, 2026
CVE-2026-53681 UNKNOWN — Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. Sep 17, 2026