Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25301
Total
1888
Critical
7733
High
7926
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-52766 | MEDIUM | 6.5 | Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from … | Jun 02, 2026 |
| CVE-2025-52759 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a … | Jun 02, 2026 |
| CVE-2026-9730 | MEDIUM | 4.3 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due … | Jun 02, 2026 |
| CVE-2026-9723 | MEDIUM | 4.3 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due … | Jun 02, 2026 |
| CVE-2026-9722 | MEDIUM | 4.3 | The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing … | Jun 02, 2026 |
| CVE-2026-9599 | MEDIUM | 4.3 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing … | Jun 02, 2026 |
| CVE-2026-9234 | MEDIUM | 4.3 | The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability … | Jun 02, 2026 |
| CVE-2026-8885 | MEDIUM | 6.4 | The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. … | Jun 02, 2026 |
| CVE-2026-8422 | MEDIUM | 4.3 | The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This … | Jun 02, 2026 |
| CVE-2026-4081 | MEDIUM | 6.4 | The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This … | Jun 02, 2026 |
| CVE-2026-4080 | MEDIUM | 6.4 | The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This … | Jun 02, 2026 |
| CVE-2026-4071 | MEDIUM | 4.3 | The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce … | Jun 02, 2026 |
| CVE-2026-3620 | MEDIUM | 4.4 | The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This … | Jun 02, 2026 |
| CVE-2026-3514 | HIGH | 7.5 | In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the … | Jun 02, 2026 |
| CVE-2026-2425 | MEDIUM | 6.1 | The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 … | Jun 02, 2026 |
| CVE-2026-2382 | MEDIUM | 6.4 | The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions … | Jun 02, 2026 |
| CVE-2026-1784 | HIGH | 8.8 | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on … | Jun 02, 2026 |
| CVE-2026-1451 | MEDIUM | 6.1 | The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient … | Jun 02, 2026 |
| CVE-2026-1450 | MEDIUM | 6.1 | The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient … | Jun 02, 2026 |
| CVE-2025-5085 | MEDIUM | 5.5 | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 … | Jun 02, 2026 |
| CVE-2026-8293 | HIGH | 7.5 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker … | Jun 02, 2026 |
| CVE-2026-8206 | CRITICAL | 9.8 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 … | Jun 02, 2026 |
| CVE-2026-3198 | MEDIUM | 6.5 | MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not … | Jun 02, 2026 |
| CVE-2026-10583 | MEDIUM | 4.7 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of … | Jun 02, 2026 |
| CVE-2026-10581 | MEDIUM | 6.3 | A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument … | Jun 02, 2026 |