Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92727 | MEDIUM | 6.4 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site … | Oct 03, 2026 |
| CVE-2026-92551 | MEDIUM | 6.1 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site … | Oct 03, 2026 |
| CVE-2026-92538 | MEDIUM | 6.1 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' … | Oct 03, 2026 |
| CVE-2026-92536 | HIGH | 8.8 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information … | Oct 03, 2026 |
| CVE-2026-96270 | HIGH | 7.2 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Oct 03, 2026 |
| CVE-2026-95865 | MEDIUM | 6.5 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all … | Oct 03, 2026 |
| CVE-2026-94539 | MEDIUM | 6.5 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter … | Oct 03, 2026 |
| CVE-2026-94378 | MEDIUM | 6.4 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter … | Oct 03, 2026 |
| CVE-2026-93428 | HIGH | 7.5 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all … | Oct 03, 2026 |
| CVE-2026-92243 | MEDIUM | 6.1 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, … | Oct 03, 2026 |
| CVE-2026-100180 | MEDIUM | 5.4 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Oct 03, 2026 |
| CVE-2026-105090 | UNKNOWN | — | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A … | Oct 03, 2026 |
| CVE-2026-105083 | LOW | 3.9 | ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A … | Oct 03, 2026 |
| CVE-2026-79113 | UNKNOWN | — | OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. | Oct 03, 2026 |
| CVE-2026-105080 | CRITICAL | 9.9 | In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in … | Oct 03, 2026 |
| CVE-2026-105030 | MEDIUM | 5.3 | Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers … | Oct 03, 2026 |
| CVE-2026-105029 | MEDIUM | 4.3 | UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' … | Oct 03, 2026 |
| CVE-2026-104479 | MEDIUM | 5.4 | Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is … | Oct 03, 2026 |
| CVE-2026-104478 | HIGH | 7.1 | Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download … | Oct 03, 2026 |
| CVE-2026-104477 | MEDIUM | 6.1 | Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed … | Oct 03, 2026 |
| CVE-2026-104476 | MEDIUM | 5.9 | Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers … | Oct 03, 2026 |
| CVE-2026-104475 | MEDIUM | 5.4 | IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can … | Oct 03, 2026 |
| CVE-2026-104474 | MEDIUM | 6.7 | OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the … | Oct 03, 2026 |
| CVE-2026-104433 | HIGH | 7.5 | Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by … | Oct 03, 2026 |
| CVE-2026-84411 | CRITICAL | 9.8 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can … | Oct 02, 2026 |