Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-102580 LOW 2.2 A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class … Sep 30, 2026
CVE-2026-102579 MEDIUM 4.3 A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other … Sep 30, 2026
CVE-2026-102578 MEDIUM 5.5 A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, … Sep 30, 2026
CVE-2026-102577 MEDIUM 4.3 A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass … Sep 30, 2026
CVE-2026-102511 UNKNOWN — Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to … Sep 30, 2026
CVE-2026-102510 UNKNOWN — Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow … Sep 30, 2026
CVE-2026-102509 UNKNOWN — Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious … Sep 30, 2026
CVE-2026-102459 MEDIUM 6.1 EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks. Sep 30, 2026
CVE-2026-102458 CRITICAL 9.8 EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API. Sep 30, 2026
CVE-2026-102457 MEDIUM 6.5 EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files. Sep 30, 2026
CVE-2026-102456 MEDIUM 6.5 EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents. Sep 30, 2026
CVE-2026-102455 CRITICAL 9.8 EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized … Sep 30, 2026
CVE-2026-102454 HIGH 7.2 EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code … Sep 30, 2026
CVE-2025-14564 MEDIUM 6.4 The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, … Sep 30, 2026
CVE-2026-97150 HIGH 7.2 When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files … Sep 30, 2026
CVE-2026-93464 MEDIUM 5.4 Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the … Sep 30, 2026
CVE-2026-93463 MEDIUM 5.4 Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser … Sep 30, 2026
CVE-2026-93462 MEDIUM 5.3 Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained. Sep 30, 2026
CVE-2026-93460 MEDIUM 5.4 Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be … Sep 30, 2026
CVE-2026-92873 HIGH 7.3 Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. Sep 30, 2026
CVE-2026-92872 MEDIUM 4.3 Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. Sep 30, 2026
CVE-2026-92871 HIGH 7.5 A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. Sep 30, 2026
CVE-2026-92870 HIGH 7.5 A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. Sep 30, 2026
CVE-2026-92869 MEDIUM 6.5 An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. Sep 30, 2026
CVE-2026-92868 MEDIUM 6.5 An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. Sep 30, 2026