Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89190 | MEDIUM | 4.3 | The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing … | Sep 30, 2026 |
| CVE-2026-88797 | HIGH | 7.1 | The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it … | Sep 30, 2026 |
| CVE-2026-88791 | LOW | 3.4 | The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is … | Sep 30, 2026 |
| CVE-2026-87777 | MEDIUM | 6.8 | The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with … | Sep 30, 2026 |
| CVE-2026-86789 | MEDIUM | 5.3 | The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers … | Sep 30, 2026 |
| CVE-2026-85576 | MEDIUM | 4.3 | The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, … | Sep 30, 2026 |
| CVE-2026-85573 | HIGH | 8.8 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or … | Sep 30, 2026 |
| CVE-2026-85415 | MEDIUM | 6.8 | The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing … | Sep 30, 2026 |
| CVE-2026-85001 | MEDIUM | 6.8 | The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which … | Sep 30, 2026 |
| CVE-2026-83560 | MEDIUM | 5.3 | The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is … | Sep 30, 2026 |
| CVE-2026-82127 | LOW | 3.5 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, … | Sep 30, 2026 |
| CVE-2026-80333 | MEDIUM | 5.3 | The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read … | Sep 30, 2026 |
| CVE-2026-75873 | CRITICAL | 9.8 | The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available … | Sep 30, 2026 |
| CVE-2026-75824 | MEDIUM | 5.3 | The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create … | Sep 30, 2026 |
| CVE-2026-75823 | HIGH | 7.4 | The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with … | Sep 30, 2026 |
| CVE-2026-100143 | MEDIUM | 6.5 | The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address … | Sep 30, 2026 |
| CVE-2026-103111 | HIGH | 7.6 | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data. | Sep 30, 2026 |
| CVE-2026-102913 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation … | Sep 30, 2026 |
| CVE-2026-86134 | UNKNOWN | — | A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a … | Sep 30, 2026 |
| CVE-2026-103110 | CRITICAL | 9.8 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as … | Sep 30, 2026 |
| CVE-2026-102912 | MEDIUM | 4.7 | A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the … | Sep 30, 2026 |
| CVE-2026-102911 | CRITICAL | 9.9 | A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP … | Sep 30, 2026 |
| CVE-2026-102910 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The … | Sep 30, 2026 |
| CVE-2026-96649 | HIGH | 7.2 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label … | Sep 30, 2026 |
| CVE-2026-86556 | MEDIUM | 5.3 | There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information. | Sep 30, 2026 |