Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93771 | HIGH | 7.2 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | Sep 30, 2026 |
| CVE-2026-93770 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | Sep 30, 2026 |
| CVE-2026-93651 | HIGH | 7.2 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | Sep 30, 2026 |
| CVE-2026-93624 | HIGH | 7.2 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | Sep 30, 2026 |
| CVE-2026-93621 | HIGH | 8.2 | Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | Sep 30, 2026 |
| CVE-2026-93514 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | Sep 30, 2026 |
| CVE-2026-93512 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | Sep 30, 2026 |
| CVE-2026-92899 | MEDIUM | 4.8 | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, … | Sep 30, 2026 |
| CVE-2026-92121 | HIGH | 7.5 | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer … | Sep 30, 2026 |
| CVE-2026-89238 | CRITICAL | 9.1 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are … | Sep 30, 2026 |
| CVE-2026-86778 | MEDIUM | 5.3 | Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from … | Sep 30, 2026 |
| CVE-2026-76504 | CRITICAL | 9.8 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with … | Sep 30, 2026 |
| CVE-2026-74865 | UNKNOWN | — | sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username … | Sep 30, 2026 |
| CVE-2026-74864 | UNKNOWN | — | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing … | Sep 30, 2026 |
| CVE-2026-62085 | HIGH | 7.6 | Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | Sep 30, 2026 |
| CVE-2026-62083 | MEDIUM | 5.4 | Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. | Sep 30, 2026 |
| CVE-2026-62081 | MEDIUM | 5.4 | Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. | Sep 30, 2026 |
| CVE-2026-62080 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | Sep 30, 2026 |
| CVE-2026-62079 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | Sep 30, 2026 |
| CVE-2026-62078 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | Sep 30, 2026 |
| CVE-2026-27371 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | Sep 30, 2026 |
| CVE-2026-27085 | LOW | 2.7 | Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | Sep 30, 2026 |
| CVE-2026-103321 | UNKNOWN | — | MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without … | Sep 30, 2026 |
| CVE-2026-103117 | MEDIUM | 4.7 | A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save … | Sep 30, 2026 |
| CVE-2026-103116 | MEDIUM | 6.3 | A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List … | Sep 30, 2026 |