Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-103115 MEDIUM 6.3 A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student … Sep 30, 2026
CVE-2026-102399 MEDIUM 5.4 Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. Sep 30, 2026
CVE-2026-102398 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions. Sep 30, 2026
CVE-2026-102396 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. Sep 30, 2026
CVE-2026-102395 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. Sep 30, 2026
CVE-2026-102386 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. Sep 30, 2026
CVE-2026-102385 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. Sep 30, 2026
CVE-2026-102384 MEDIUM 5.9 Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. Sep 30, 2026
CVE-2026-100513 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions. Sep 30, 2026
CVE-2026-100508 MEDIUM 5.3 Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. Sep 30, 2026
CVE-2026-100507 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. Sep 30, 2026
CVE-2026-88920 CRITICAL 9.8 An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML … Sep 30, 2026
CVE-2026-87830 CRITICAL 9.1 In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. … Sep 30, 2026
CVE-2026-85532 HIGH 7.5 Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing … Sep 30, 2026
CVE-2026-62146 HIGH 7.8 A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a … Sep 30, 2026
CVE-2026-10739 UNKNOWN — Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied … Sep 30, 2026
CVE-2026-10726 UNKNOWN — Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local … Sep 30, 2026
CVE-2026-103242 HIGH 7.1 A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, … Sep 30, 2026
CVE-2026-103114 MEDIUM 6.3 A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment … Sep 30, 2026
CVE-2026-103012 UNKNOWN — Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the … Sep 30, 2026
CVE-2026-96342 UNKNOWN — Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. Sep 30, 2026
CVE-2026-76992 HIGH 7.5 The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker … Sep 30, 2026
CVE-2026-13720 MEDIUM 5.4 An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored … Sep 30, 2026
CVE-2026-13719 MEDIUM 4.3 An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the … Sep 30, 2026
CVE-2026-103239 UNKNOWN — MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed … Sep 30, 2026