Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29082
Total
2258
Critical
8681
High
9062
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-4121 | MEDIUM | 4.3 | The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce … | Apr 22, 2026 |
| CVE-2026-4119 | CRITICAL | 9.1 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action … | Apr 22, 2026 |
| CVE-2026-4118 | MEDIUM | 4.3 | The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due … | Apr 22, 2026 |
| CVE-2026-4117 | MEDIUM | 5.3 | The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability … | Apr 22, 2026 |
| CVE-2026-4090 | MEDIUM | 6.1 | The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing … | Apr 22, 2026 |
| CVE-2026-4089 | MEDIUM | 6.4 | The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and including … | Apr 22, 2026 |
| CVE-2026-4088 | MEDIUM | 6.4 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. … | Apr 22, 2026 |
| CVE-2026-4085 | MEDIUM | 6.4 | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the 'my-instagram-feed' shortcode in all … | Apr 22, 2026 |
| CVE-2026-4082 | MEDIUM | 6.4 | The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including 1.0.0. … | Apr 22, 2026 |
| CVE-2026-4076 | MEDIUM | 6.4 | The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to … | Apr 22, 2026 |
| CVE-2026-4074 | MEDIUM | 6.4 | The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in all versions up to, … | Apr 22, 2026 |
| CVE-2026-3362 | MEDIUM | 4.4 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' settings field in all versions up to and … | Apr 22, 2026 |
| CVE-2026-31433 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for compound requests When a compound request consists of … | Apr 22, 2026 |
| CVE-2026-31432 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as … | Apr 22, 2026 |
| CVE-2026-31431 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the … | Apr 22, 2026 |
| CVE-2026-2719 | MEDIUM | 4.4 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in all versions up to, and including, 0.4.1. … | Apr 22, 2026 |
| CVE-2026-2717 | MEDIUM | 5.5 | The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This is due to insufficient sanitization … | Apr 22, 2026 |
| CVE-2026-2714 | MEDIUM | 4.4 | The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Enquiry Form Title' setting in all versions up to, and including, … | Apr 22, 2026 |
| CVE-2026-1845 | MEDIUM | 5.5 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due … | Apr 22, 2026 |
| CVE-2026-1379 | MEDIUM | 4.4 | The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.2 due to … | Apr 22, 2026 |
| CVE-2026-6842 | LOW | 2.5 | A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for … | Apr 22, 2026 |
| CVE-2026-6023 | HIGH | 8.1 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state … | Apr 22, 2026 |
| CVE-2026-6022 | HIGH | 7.5 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum … | Apr 22, 2026 |
| CVE-2026-40542 | HIGH | 7.3 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. … | Apr 22, 2026 |
| CVE-2026-6840 | MEDIUM | 5.5 | Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0. | Apr 22, 2026 |