Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25592
Total
1903
Critical
7807
High
8024
Medium
CVE ID Severity Score Description Published
CVE-2026-49201 UNKNOWN The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, … May 29, 2026
CVE-2026-46579 HIGH 7.4 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from … May 29, 2026
CVE-2026-42965 HIGH 7.7 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an … May 29, 2026
CVE-2026-10078 LOW 2.7 A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext … May 29, 2026
CVE-2025-12714 MEDIUM 5.3 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability … May 29, 2026
CVE-2026-9189 MEDIUM 5.3 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all … May 29, 2026
CVE-2026-6075 HIGH 8.1 The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing … May 29, 2026
CVE-2026-49200 UNKNOWN The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), … May 29, 2026
CVE-2026-49199 UNKNOWN Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. May 29, 2026
CVE-2026-49198 UNKNOWN Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. May 29, 2026
CVE-2026-49197 UNKNOWN Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. May 29, 2026
CVE-2026-49196 UNKNOWN The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. May 29, 2026
CVE-2026-49195 UNKNOWN Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. May 29, 2026
CVE-2026-10058 MEDIUM 4.8 ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … May 29, 2026
CVE-2026-10057 MEDIUM 4.8 ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … May 29, 2026
CVE-2026-10056 HIGH 7.5 CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux … May 29, 2026
CVE-2026-10052 MEDIUM 4.1 A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make … May 29, 2026
CVE-2026-10039 MEDIUM 4.9 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, … May 29, 2026
CVE-2026-9243 MEDIUM 6.4 The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions … May 29, 2026
CVE-2026-4776 HIGH 7.1 An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can … May 29, 2026
CVE-2026-49322 MEDIUM 4.3 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read … May 29, 2026
CVE-2026-3655 CRITICAL 9.8 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to … May 29, 2026
CVE-2025-11262 HIGH 7.2 The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 … May 29, 2026
CVE-2026-9714 MEDIUM 6.4 The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, … May 29, 2026
CVE-2026-9493 MEDIUM 6.5 Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific … May 29, 2026