Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-89190 MEDIUM 4.3 The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing … Sep 30, 2026
CVE-2026-88797 HIGH 7.1 The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it … Sep 30, 2026
CVE-2026-88791 LOW 3.4 The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is … Sep 30, 2026
CVE-2026-87777 MEDIUM 6.8 The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with … Sep 30, 2026
CVE-2026-86789 MEDIUM 5.3 The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers … Sep 30, 2026
CVE-2026-85576 MEDIUM 4.3 The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, … Sep 30, 2026
CVE-2026-85573 HIGH 8.8 The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or … Sep 30, 2026
CVE-2026-85415 MEDIUM 6.8 The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing … Sep 30, 2026
CVE-2026-85001 MEDIUM 6.8 The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which … Sep 30, 2026
CVE-2026-83560 MEDIUM 5.3 The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is … Sep 30, 2026
CVE-2026-82127 LOW 3.5 The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, … Sep 30, 2026
CVE-2026-80333 MEDIUM 5.3 The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read … Sep 30, 2026
CVE-2026-75873 CRITICAL 9.8 The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available … Sep 30, 2026
CVE-2026-75824 MEDIUM 5.3 The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create … Sep 30, 2026
CVE-2026-75823 HIGH 7.4 The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with … Sep 30, 2026
CVE-2026-100143 MEDIUM 6.5 The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address … Sep 30, 2026
CVE-2026-103111 HIGH 7.6 PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data. Sep 30, 2026
CVE-2026-102913 HIGH 7.3 A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation … Sep 30, 2026
CVE-2026-86134 UNKNOWN — A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a … Sep 30, 2026
CVE-2026-103110 CRITICAL 9.8 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as … Sep 30, 2026
CVE-2026-102912 MEDIUM 4.7 A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the … Sep 30, 2026
CVE-2026-102911 CRITICAL 9.9 A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP … Sep 30, 2026
CVE-2026-102910 HIGH 7.3 A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The … Sep 30, 2026
CVE-2026-96649 HIGH 7.2 The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label … Sep 30, 2026
CVE-2026-86556 MEDIUM 5.3 There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information. Sep 30, 2026