Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2026-86210 HIGH 7.3 A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file … Sep 06, 2026
CVE-2026-86209 HIGH 7.3 A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of … Sep 06, 2026
CVE-2026-86208 HIGH 7.3 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation … Sep 06, 2026
CVE-2026-80439 MEDIUM 4.8 The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it … Sep 06, 2026
CVE-2026-80437 MEDIUM 4.8 The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content … Sep 06, 2026
CVE-2026-19862 MEDIUM 4.8 The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them … Sep 06, 2026
CVE-2026-19859 MEDIUM 6.5 The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes … Sep 06, 2026
CVE-2026-86183 MEDIUM 5.3 A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation … Sep 06, 2026
CVE-2026-86182 MEDIUM 4.3 A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation … Sep 06, 2026
CVE-2026-86181 LOW 3.5 A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component … Sep 06, 2026
CVE-2026-86180 HIGH 7.3 A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php … Sep 06, 2026
CVE-2026-86179 MEDIUM 5.3 A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup … Sep 06, 2026
CVE-2026-86172 MEDIUM 6.3 A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results … Sep 06, 2026
CVE-2026-86171 MEDIUM 6.3 A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID … Sep 06, 2026
CVE-2026-85038 UNKNOWN The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that … Sep 06, 2026
CVE-2026-84219 UNKNOWN The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store … Sep 06, 2026
CVE-2026-84028 UNKNOWN The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users … Sep 06, 2026
CVE-2026-75793 UNKNOWN The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account … Sep 06, 2026
CVE-2026-18480 UNKNOWN The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, … Sep 06, 2026
CVE-2026-13159 UNKNOWN The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, … Sep 06, 2026
CVE-2026-86170 MEDIUM 6.3 A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument … Sep 06, 2026
CVE-2026-86168 HIGH 7.3 A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation … Sep 06, 2026
CVE-2026-86167 CRITICAL 9.9 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the … Sep 06, 2026
CVE-2026-86166 HIGH 8.8 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing … Sep 06, 2026
CVE-2026-86165 CRITICAL 9.8 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN … Sep 06, 2026