Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9511 | MEDIUM | 6.3 | A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of … | May 25, 2026 |
| CVE-2026-9504 | LOW | 3.3 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. … | May 25, 2026 |
| CVE-2026-27398 | MEDIUM | 5.3 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: … | May 25, 2026 |
| CVE-2026-27357 | MEDIUM | 5.3 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a … | May 25, 2026 |
| CVE-2026-27346 | MEDIUM | 4.9 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10. | May 25, 2026 |
| CVE-2026-24592 | MEDIUM | 5.3 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a … | May 25, 2026 |
| CVE-2026-24586 | MEDIUM | 5.4 | Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77. | May 25, 2026 |
| CVE-2026-24582 | MEDIUM | 4.3 | Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0. | May 25, 2026 |
| CVE-2026-24554 | MEDIUM | 4.3 | Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1. | May 25, 2026 |
| CVE-2026-24527 | MEDIUM | 4.3 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects … | May 25, 2026 |
| CVE-2025-62745 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a … | May 25, 2026 |
| CVE-2026-9503 | LOW | 3.3 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG … | May 25, 2026 |
| CVE-2026-9502 | MEDIUM | 5.3 | A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The … | May 25, 2026 |
| CVE-2026-9501 | LOW | 3.3 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread … | May 25, 2026 |
| CVE-2026-9500 | MEDIUM | 5.3 | A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread … | May 25, 2026 |
| CVE-2026-48852 | LOW | 3.7 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. | May 25, 2026 |
| CVE-2026-48851 | LOW | 3.1 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared … | May 25, 2026 |
| CVE-2026-48850 | LOW | 3.7 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. | May 25, 2026 |
| CVE-2026-48589 | UNKNOWN | — | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation … | May 25, 2026 |
| CVE-2026-44598 | UNKNOWN | — | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from … | May 25, 2026 |
| CVE-2026-43828 | UNKNOWN | — | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. … | May 25, 2026 |
| CVE-2026-43827 | UNKNOWN | — | Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to … | May 25, 2026 |
| CVE-2026-24597 | MEDIUM | 4.3 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5. | May 25, 2026 |
| CVE-2026-24574 | MEDIUM | 6.5 | Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to … | May 25, 2026 |
| CVE-2026-24545 | MEDIUM | 4.3 | Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3. | May 25, 2026 |