Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86210 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file … | Sep 06, 2026 |
| CVE-2026-86209 | HIGH | 7.3 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of … | Sep 06, 2026 |
| CVE-2026-86208 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation … | Sep 06, 2026 |
| CVE-2026-80439 | MEDIUM | 4.8 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it … | Sep 06, 2026 |
| CVE-2026-80437 | MEDIUM | 4.8 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content … | Sep 06, 2026 |
| CVE-2026-19862 | MEDIUM | 4.8 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them … | Sep 06, 2026 |
| CVE-2026-19859 | MEDIUM | 6.5 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes … | Sep 06, 2026 |
| CVE-2026-86183 | MEDIUM | 5.3 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation … | Sep 06, 2026 |
| CVE-2026-86182 | MEDIUM | 4.3 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation … | Sep 06, 2026 |
| CVE-2026-86181 | LOW | 3.5 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component … | Sep 06, 2026 |
| CVE-2026-86180 | HIGH | 7.3 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php … | Sep 06, 2026 |
| CVE-2026-86179 | MEDIUM | 5.3 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup … | Sep 06, 2026 |
| CVE-2026-86172 | MEDIUM | 6.3 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results … | Sep 06, 2026 |
| CVE-2026-86171 | MEDIUM | 6.3 | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID … | Sep 06, 2026 |
| CVE-2026-85038 | UNKNOWN | — | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that … | Sep 06, 2026 |
| CVE-2026-84219 | UNKNOWN | — | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store … | Sep 06, 2026 |
| CVE-2026-84028 | UNKNOWN | — | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users … | Sep 06, 2026 |
| CVE-2026-75793 | UNKNOWN | — | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account … | Sep 06, 2026 |
| CVE-2026-18480 | UNKNOWN | — | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, … | Sep 06, 2026 |
| CVE-2026-13159 | UNKNOWN | — | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, … | Sep 06, 2026 |
| CVE-2026-86170 | MEDIUM | 6.3 | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument … | Sep 06, 2026 |
| CVE-2026-86168 | HIGH | 7.3 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation … | Sep 06, 2026 |
| CVE-2026-86167 | CRITICAL | 9.9 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the … | Sep 06, 2026 |
| CVE-2026-86166 | HIGH | 8.8 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing … | Sep 06, 2026 |
| CVE-2026-86165 | CRITICAL | 9.8 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN … | Sep 06, 2026 |