Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-95587 HIGH 7.5 Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. Sep 30, 2026
CVE-2026-95531 HIGH 8.8 Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. Sep 30, 2026
CVE-2026-94683 HIGH 8.8 Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. Sep 30, 2026
CVE-2026-94681 MEDIUM 5.9 Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions. Sep 30, 2026
CVE-2026-94678 HIGH 8.8 Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. Sep 30, 2026
CVE-2026-94677 HIGH 7.2 Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. Sep 30, 2026
CVE-2026-94674 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. Sep 30, 2026
CVE-2026-94673 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. Sep 30, 2026
CVE-2026-94672 MEDIUM 4.3 Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. Sep 30, 2026
CVE-2026-94499 HIGH 7.1 Subscriber Broken Access Control in FormGent <= 1.12.2 versions. Sep 30, 2026
CVE-2026-94389 CRITICAL 9.0 Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. Sep 30, 2026
CVE-2026-94178 HIGH 7.5 Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. Sep 30, 2026
CVE-2026-94177 HIGH 8.5 Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. Sep 30, 2026
CVE-2026-94173 MEDIUM 5.4 Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions. Sep 30, 2026
CVE-2026-94123 HIGH 7.5 Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. Sep 30, 2026
CVE-2026-94122 HIGH 7.2 Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. Sep 30, 2026
CVE-2026-94121 HIGH 8.8 Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. Sep 30, 2026
CVE-2026-94120 HIGH 7.5 Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. Sep 30, 2026
CVE-2026-94115 HIGH 8.5 Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. Sep 30, 2026
CVE-2026-94082 HIGH 7.6 Author SQL Injection in Quiz Cat <= 3.1.1 versions. Sep 30, 2026
CVE-2026-94081 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. Sep 30, 2026
CVE-2026-94078 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. Sep 30, 2026
CVE-2026-94077 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. Sep 30, 2026
CVE-2026-94076 HIGH 8.8 Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. Sep 30, 2026
CVE-2026-94074 MEDIUM 6.5 Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. Sep 30, 2026