Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-93771 HIGH 7.2 Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. Sep 30, 2026
CVE-2026-93770 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. Sep 30, 2026
CVE-2026-93651 HIGH 7.2 Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. Sep 30, 2026
CVE-2026-93624 HIGH 7.2 Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. Sep 30, 2026
CVE-2026-93621 HIGH 8.2 Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. Sep 30, 2026
CVE-2026-93514 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. Sep 30, 2026
CVE-2026-93512 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. Sep 30, 2026
CVE-2026-92899 MEDIUM 4.8 Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, … Sep 30, 2026
CVE-2026-92121 HIGH 7.5 In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer … Sep 30, 2026
CVE-2026-89238 CRITICAL 9.1 WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are … Sep 30, 2026
CVE-2026-86778 MEDIUM 5.3 Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from … Sep 30, 2026
CVE-2026-76504 CRITICAL 9.8 A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with … Sep 30, 2026
CVE-2026-74865 UNKNOWN — sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username … Sep 30, 2026
CVE-2026-74864 UNKNOWN — sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing … Sep 30, 2026
CVE-2026-62085 HIGH 7.6 Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. Sep 30, 2026
CVE-2026-62083 MEDIUM 5.4 Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. Sep 30, 2026
CVE-2026-62081 MEDIUM 5.4 Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. Sep 30, 2026
CVE-2026-62080 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. Sep 30, 2026
CVE-2026-62079 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. Sep 30, 2026
CVE-2026-62078 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. Sep 30, 2026
CVE-2026-27371 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. Sep 30, 2026
CVE-2026-27085 LOW 2.7 Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. Sep 30, 2026
CVE-2026-103321 UNKNOWN — MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without … Sep 30, 2026
CVE-2026-103117 MEDIUM 4.7 A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save … Sep 30, 2026
CVE-2026-103116 MEDIUM 6.3 A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List … Sep 30, 2026