Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28078
Total
2162
Critical
8456
High
8753
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7332 | HIGH | 7.2 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all … | May 06, 2026 |
| CVE-2026-6672 | MEDIUM | 6.4 | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and … | May 06, 2026 |
| CVE-2026-6344 | MEDIUM | 4.9 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path … | May 06, 2026 |
| CVE-2026-35254 | MEDIUM | 6.1 | Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated … | May 06, 2026 |
| CVE-2026-35253 | MEDIUM | 4.7 | Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated … | May 06, 2026 |
| CVE-2026-23928 | UNKNOWN | — | The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This … | May 06, 2026 |
| CVE-2026-23927 | UNKNOWN | — | A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 … | May 06, 2026 |
| CVE-2026-23926 | UNKNOWN | — | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance … | May 06, 2026 |
| CVE-2026-2306 | MEDIUM | 4.3 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the … | May 06, 2026 |
| CVE-2026-5753 | MEDIUM | 6.5 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to … | May 06, 2026 |
| CVE-2026-3208 | MEDIUM | 5.3 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' … | May 06, 2026 |
| CVE-2026-7573 | MEDIUM | 5.0 | An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete … | May 06, 2026 |
| CVE-2026-7572 | MEDIUM | 4.4 | An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to … | May 06, 2026 |
| CVE-2025-71256 | HIGH | 7.5 | In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 06, 2026 |
| CVE-2025-71255 | HIGH | 7.5 | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 06, 2026 |
| CVE-2025-71254 | HIGH | 7.5 | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 06, 2026 |
| CVE-2025-71253 | HIGH | 7.5 | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 06, 2026 |
| CVE-2025-71252 | HIGH | 7.5 | In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. | May 06, 2026 |
| CVE-2025-71251 | HIGH | 7.5 | In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution … | May 06, 2026 |
| CVE-2026-44405 | LOW | 3.4 | In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. | May 06, 2026 |
| CVE-2026-40934 | UNKNOWN | — | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a … | May 05, 2026 |
| CVE-2026-40110 | UNKNOWN | — | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins … | May 05, 2026 |
| CVE-2026-40075 | UNKNOWN | — | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is … | May 05, 2026 |
| CVE-2026-28780 | CRITICAL | 9.8 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious … | May 05, 2026 |
| CVE-2026-41950 | MEDIUM | 6.5 | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within … | May 05, 2026 |