Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93547 | UNKNOWN | — | A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell … | Sep 30, 2026 |
| CVE-2026-91860 | UNKNOWN | — | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control … | Sep 30, 2026 |
| CVE-2026-82307 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: … | Sep 30, 2026 |
| CVE-2026-103118 | MEDIUM | 4.3 | A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG … | Sep 30, 2026 |
| CVE-2026-97302 | MEDIUM | 5.3 | Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions. | Sep 30, 2026 |
| CVE-2026-97301 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions. | Sep 30, 2026 |
| CVE-2026-97299 | MEDIUM | 5.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | Sep 30, 2026 |
| CVE-2026-97298 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. | Sep 30, 2026 |
| CVE-2026-97293 | HIGH | 8.5 | Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. | Sep 30, 2026 |
| CVE-2026-97292 | MEDIUM | 6.5 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | Sep 30, 2026 |
| CVE-2026-97289 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | Sep 30, 2026 |
| CVE-2026-97288 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | Sep 30, 2026 |
| CVE-2026-97287 | HIGH | 8.5 | Contributor SQL Injection in Event Tickets <= 5.29.5 versions. | Sep 30, 2026 |
| CVE-2026-97286 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions. | Sep 30, 2026 |
| CVE-2026-97285 | MEDIUM | 5.4 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | Sep 30, 2026 |
| CVE-2026-97282 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | Sep 30, 2026 |
| CVE-2026-97279 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. | Sep 30, 2026 |
| CVE-2026-97274 | CRITICAL | 9.8 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | Sep 30, 2026 |
| CVE-2026-97272 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. | Sep 30, 2026 |
| CVE-2026-97271 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | Sep 30, 2026 |
| CVE-2026-97270 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions. | Sep 30, 2026 |
| CVE-2026-97267 | MEDIUM | 4.3 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | Sep 30, 2026 |
| CVE-2026-97266 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions. | Sep 30, 2026 |
| CVE-2026-97262 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | Sep 30, 2026 |
| CVE-2026-97261 | MEDIUM | 5.3 | Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions. | Sep 30, 2026 |