Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

11702
Total
781
Critical
3315
High
3732
Medium
CVE ID Severity Score Description Published
CVE-2026-33273 MEDIUM 4.7 Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be … Apr 08, 2026
CVE-2026-27787 MEDIUM 5.4 Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser … Apr 08, 2026
CVE-2026-24913 HIGH 8.8 SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered … Apr 08, 2026
CVE-2026-4785 MEDIUM 6.4 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the … Apr 08, 2026
CVE-2026-4341 MEDIUM 6.4 The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in … Apr 08, 2026
CVE-2026-4333 MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all … Apr 08, 2026
CVE-2026-4299 MEDIUM 5.3 The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a … Apr 08, 2026
CVE-2026-4003 CRITICAL 9.8 The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including … Apr 08, 2026
CVE-2026-3646 MEDIUM 5.3 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up … Apr 08, 2026
CVE-2026-3600 MEDIUM 6.4 The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all versions up to, and including, 1.0.26. … Apr 08, 2026
CVE-2026-3513 MEDIUM 6.4 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to … Apr 08, 2026
CVE-2026-3239 MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 … Apr 08, 2026
CVE-2026-4379 MEDIUM 6.4 The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, … Apr 08, 2026
CVE-2026-2988 MEDIUM 6.4 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 … Apr 08, 2026
CVE-2026-5726 HIGH 7.8 ASDA-Soft Stack-based Buffer Overflow Vulnerability Apr 08, 2026
CVE-2026-1163 MEDIUM 4.1 An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an … Apr 08, 2026
CVE-2026-3499 HIGH 8.8 The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 … Apr 08, 2026
CVE-2026-3296 CRITICAL 9.8 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input … Apr 08, 2026
CVE-2026-33810 UNKNOWN When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than … Apr 08, 2026
CVE-2026-32289 UNKNOWN Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template … Apr 08, 2026
CVE-2026-32288 UNKNOWN tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU … Apr 08, 2026
CVE-2026-32283 UNKNOWN If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of … Apr 08, 2026
CVE-2026-32282 UNKNOWN On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target … Apr 08, 2026
CVE-2026-32281 UNKNOWN Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial … Apr 08, 2026
CVE-2026-32280 HIGH 7.5 During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, … Apr 08, 2026