Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25301
Total
1888
Critical
7733
High
7926
Medium
CVE ID Severity Score Description Published
CVE-2025-52766 MEDIUM 6.5 Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from … Jun 02, 2026
CVE-2025-52759 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a … Jun 02, 2026
CVE-2026-9730 MEDIUM 4.3 The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due … Jun 02, 2026
CVE-2026-9723 MEDIUM 4.3 The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due … Jun 02, 2026
CVE-2026-9722 MEDIUM 4.3 The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing … Jun 02, 2026
CVE-2026-9599 MEDIUM 4.3 The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing … Jun 02, 2026
CVE-2026-9234 MEDIUM 4.3 The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability … Jun 02, 2026
CVE-2026-8885 MEDIUM 6.4 The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. … Jun 02, 2026
CVE-2026-8422 MEDIUM 4.3 The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This … Jun 02, 2026
CVE-2026-4081 MEDIUM 6.4 The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This … Jun 02, 2026
CVE-2026-4080 MEDIUM 6.4 The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This … Jun 02, 2026
CVE-2026-4071 MEDIUM 4.3 The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce … Jun 02, 2026
CVE-2026-3620 MEDIUM 4.4 The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This … Jun 02, 2026
CVE-2026-3514 HIGH 7.5 In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the … Jun 02, 2026
CVE-2026-2425 MEDIUM 6.1 The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 … Jun 02, 2026
CVE-2026-2382 MEDIUM 6.4 The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions … Jun 02, 2026
CVE-2026-1784 HIGH 8.8 The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on … Jun 02, 2026
CVE-2026-1451 MEDIUM 6.1 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient … Jun 02, 2026
CVE-2026-1450 MEDIUM 6.1 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient … Jun 02, 2026
CVE-2025-5085 MEDIUM 5.5 The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 … Jun 02, 2026
CVE-2026-8293 HIGH 7.5 The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker … Jun 02, 2026
CVE-2026-8206 CRITICAL 9.8 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 … Jun 02, 2026
CVE-2026-3198 MEDIUM 6.5 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not … Jun 02, 2026
CVE-2026-10583 MEDIUM 4.7 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of … Jun 02, 2026
CVE-2026-10581 MEDIUM 6.3 A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument … Jun 02, 2026