Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76555 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly … | Sep 16, 2026 |
| CVE-2026-76553 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it … | Sep 16, 2026 |
| CVE-2026-76552 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL … | Sep 16, 2026 |
| CVE-2026-76551 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted … | Sep 16, 2026 |
| CVE-2026-76550 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export … | Sep 16, 2026 |
| CVE-2026-74926 | UNKNOWN | — | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API … | Sep 16, 2026 |
| CVE-2026-61396 | UNKNOWN | — | Rejected reason: Did not need CVE ID | Sep 16, 2026 |
| CVE-2026-89063 | HIGH | 7.5 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … | Sep 16, 2026 |
| CVE-2026-5920 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up … | Sep 16, 2026 |
| CVE-2026-18555 | MEDIUM | 6.1 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | Sep 16, 2026 |
| CVE-2026-78088 | HIGH | 8.8 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in … | Sep 16, 2026 |
| CVE-2026-18595 | HIGH | 7.2 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, … | Sep 16, 2026 |
| CVE-2026-16588 | MEDIUM | 6.5 | The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 … | Sep 16, 2026 |
| CVE-2026-14349 | CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This … | Sep 16, 2026 |
| CVE-2026-12793 | CRITICAL | 9.8 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is … | Sep 16, 2026 |
| CVE-2026-11996 | MEDIUM | 6.4 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 … | Sep 16, 2026 |
| CVE-2026-11984 | MEDIUM | 5.3 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 … | Sep 16, 2026 |
| CVE-2026-92247 | MEDIUM | 4.7 | A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin … | Sep 16, 2026 |
| CVE-2026-92221 | MEDIUM | 4.7 | A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.php. Executing a manipulation … | Sep 16, 2026 |
| CVE-2026-92220 | MEDIUM | 5.3 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a … | Sep 16, 2026 |
| CVE-2026-86109 | MEDIUM | 6.6 | The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used … | Sep 16, 2026 |
| CVE-2026-86108 | HIGH | 8.0 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted … | Sep 16, 2026 |
| CVE-2026-73450 | MEDIUM | 6.9 | On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can … | Sep 16, 2026 |
| CVE-2026-92299 | HIGH | 7.4 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. … | Sep 16, 2026 |
| CVE-2026-92298 | MEDIUM | 4.8 | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote … | Sep 16, 2026 |