Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26387
Total
1955
Critical
7970
High
8222
Medium
CVE ID Severity Score Description Published
CVE-2026-42728 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT … May 27, 2026
CVE-2026-42727 CRITICAL 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This … May 27, 2026
CVE-2026-42726 MEDIUM 6.5 Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= … May 27, 2026
CVE-2026-42725 MEDIUM 6.5 Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects … May 27, 2026
CVE-2026-3349 MEDIUM 6.1 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up … May 27, 2026
CVE-2026-3348 MEDIUM 4.4 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions … May 27, 2026
CVE-2026-3012 HIGH 8.0 A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted … May 27, 2026
CVE-2026-2288 MEDIUM 4.8 The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to … May 27, 2026
CVE-2026-2280 MEDIUM 4.8 The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient … May 27, 2026
CVE-2025-0898 MEDIUM 6.5 The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the … May 27, 2026
CVE-2026-8054 UNKNOWN Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 … May 27, 2026
CVE-2026-49002 CRITICAL 9.1 Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, … May 27, 2026
CVE-2026-48968 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a … May 27, 2026
CVE-2026-48877 MEDIUM 6.5 Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. May 27, 2026
CVE-2026-40852 HIGH 7.2 A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value … May 27, 2026
CVE-2026-40851 HIGH 8.4 A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This … May 27, 2026
CVE-2026-40850 HIGH 7.5 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL … May 27, 2026
CVE-2026-40849 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40848 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40847 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40846 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40845 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuration view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40844 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40843 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40842 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags function due to improper neutralization of special elements in a … May 27, 2026