Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26387
Total
1955
Critical
7970
High
8222
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40821 | MEDIUM | 4.9 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40819 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-40818 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-40817 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-40816 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in … | May 27, 2026 |
| CVE-2026-40815 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-40814 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in … | May 27, 2026 |
| CVE-2026-40813 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to improper neutralization of special elements in … | May 27, 2026 |
| CVE-2026-40812 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to improper neutralization of special elements in … | May 27, 2026 |
| CVE-2026-40811 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT … | May 27, 2026 |
| CVE-2026-40810 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-3897 | MEDIUM | 6.4 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, … | May 27, 2026 |
| CVE-2026-3896 | MEDIUM | 6.4 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, … | May 27, 2026 |
| CVE-2026-3895 | MEDIUM | 6.4 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up … | May 27, 2026 |
| CVE-2026-3375 | HIGH | 7.2 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, … | May 27, 2026 |
| CVE-2026-3279 | MEDIUM | 6.5 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function … | May 27, 2026 |
| CVE-2026-3001 | MEDIUM | 6.1 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to … | May 27, 2026 |
| CVE-2026-2030 | MEDIUM | 6.4 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all … | May 27, 2026 |
| CVE-2025-41670 | HIGH | 7.8 | A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located … | May 27, 2026 |
| CVE-2025-41669 | HIGH | 8.8 | The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any … | May 27, 2026 |
| CVE-2026-9200 | HIGH | 7.5 | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This … | May 27, 2026 |
| CVE-2026-9014 | MEDIUM | 5.3 | The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions … | May 27, 2026 |
| CVE-2026-8994 | HIGH | 8.1 | The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered … | May 27, 2026 |
| CVE-2026-8943 | MEDIUM | 4.3 | The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to … | May 27, 2026 |
| CVE-2026-8941 | MEDIUM | 4.3 | The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing … | May 27, 2026 |