Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40622 | UNKNOWN | — | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the … | May 20, 2026 |
| CVE-2026-35070 | MEDIUM | 6.4 | Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged … | May 20, 2026 |
| CVE-2026-33278 | CRITICAL | 9.8 | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote … | May 20, 2026 |
| CVE-2026-32792 | MEDIUM | 5.3 | NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt … | May 20, 2026 |
| CVE-2026-9065 | UNKNOWN | — | SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The … | May 20, 2026 |
| CVE-2026-9059 | UNKNOWN | — | NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The … | May 20, 2026 |
| CVE-2026-6405 | MEDIUM | 4.3 | The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in … | May 20, 2026 |
| CVE-2026-5200 | HIGH | 8.8 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, … | May 20, 2026 |
| CVE-2026-7385 | MEDIUM | 5.8 | The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API … | May 20, 2026 |
| CVE-2026-6566 | MEDIUM | 4.3 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and … | May 20, 2026 |
| CVE-2026-5776 | MEDIUM | 6.1 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks | May 20, 2026 |
| CVE-2026-47784 | HIGH | 8.1 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | May 20, 2026 |
| CVE-2026-47783 | HIGH | 8.1 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid … | May 20, 2026 |
| CVE-2026-44392 | MEDIUM | 4.3 | Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may … | May 20, 2026 |
| CVE-2026-2955 | MEDIUM | 6.4 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, … | May 20, 2026 |
| CVE-2026-9057 | HIGH | 8.2 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio … | May 20, 2026 |
| CVE-2026-9056 | MEDIUM | 5.4 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload … | May 20, 2026 |
| CVE-2026-7522 | HIGH | 8.8 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' … | May 20, 2026 |
| CVE-2026-5075 | MEDIUM | 4.3 | The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, … | May 20, 2026 |
| CVE-2026-9010 | HIGH | 7.5 | The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due … | May 20, 2026 |
| CVE-2026-9003 | HIGH | 7.5 | E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | May 20, 2026 |
| CVE-2026-7637 | CRITICAL | 9.8 | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the … | May 20, 2026 |
| CVE-2026-7460 | UNKNOWN | — | mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue … | May 20, 2026 |
| CVE-2026-24215 | MEDIUM | 5.7 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability … | May 20, 2026 |
| CVE-2026-24214 | HIGH | 8.0 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability … | May 20, 2026 |