Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57306
Total
4581
Critical
17028
High
16895
Medium
CVE ID Severity Score Description Published
CVE-2026-89141 MEDIUM 6.5 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … Sep 15, 2026
CVE-2026-75983 HIGH 7.5 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … Sep 15, 2026
CVE-2026-18063 MEDIUM 6.4 The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due … Sep 15, 2026
CVE-2026-15402 MEDIUM 6.4 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter … Sep 15, 2026
CVE-2026-91004 HIGH 7.3 A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation … Sep 15, 2026
CVE-2026-91003 CRITICAL 9.1 A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. … Sep 15, 2026
CVE-2026-91002 MEDIUM 5.3 A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist … Sep 15, 2026
CVE-2026-91001 CRITICAL 9.9 A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing … Sep 15, 2026
CVE-2026-86701 LOW 2.5 Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device … Sep 15, 2026
CVE-2026-81320 MEDIUM 5.5 A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, … Sep 15, 2026
CVE-2026-81303 MEDIUM 6.3 A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into … Sep 15, 2026
CVE-2026-18232 MEDIUM 5.3 The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of … Sep 15, 2026
CVE-2026-17495 MEDIUM 5.9 moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to … Sep 15, 2026
CVE-2026-16593 MEDIUM 6.8 The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated … Sep 15, 2026
CVE-2026-16592 LOW 2.7 The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role … Sep 15, 2026
CVE-2026-15758 MEDIUM 5.3 The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … Sep 15, 2026
CVE-2026-90881 MEDIUM 5.3 A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. … Sep 15, 2026
CVE-2026-90880 HIGH 7.4 A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing … Sep 15, 2026
CVE-2026-90879 HIGH 7.3 A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such … Sep 15, 2026
CVE-2026-90878 MEDIUM 4.3 A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. … Sep 15, 2026
CVE-2026-90877 HIGH 7.3 A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation … Sep 15, 2026
CVE-2026-90876 HIGH 7.3 A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The … Sep 15, 2026
CVE-2026-90858 HIGH 7.3 A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a … Sep 15, 2026
CVE-2026-90857 MEDIUM 6.3 A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile … Sep 15, 2026
CVE-2026-90856 HIGH 7.3 A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the … Sep 15, 2026