Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51620
Total
4095
Critical
15305
High
14964
Medium
CVE ID Severity Score Description Published
CVE-2026-16910 MEDIUM 5.5 A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing … Jul 24, 2026
CVE-2026-16519 HIGH 7.3 A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe … Jul 24, 2026
CVE-2026-15755 MEDIUM 6.4 The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, … Jul 24, 2026
CVE-2026-15665 MEDIUM 6.4 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all … Jul 24, 2026
CVE-2026-15653 MEDIUM 6.4 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in … Jul 24, 2026
CVE-2026-15648 MEDIUM 6.4 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 … Jul 24, 2026
CVE-2026-15464 MEDIUM 6.4 The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 … Jul 24, 2026
CVE-2026-15334 MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored … Jul 24, 2026
CVE-2026-15333 MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored … Jul 24, 2026
CVE-2026-12654 MEDIUM 5.3 The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due … Jul 24, 2026
CVE-2026-14603 HIGH 7.5 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of … Jul 24, 2026
CVE-2026-14172 HIGH 7.8 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code … Jul 24, 2026
CVE-2026-12981 HIGH 7.5 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password … Jul 24, 2026
CVE-2026-12877 CRITICAL 9.1 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a … Jul 24, 2026
CVE-2026-12690 LOW 3.8 The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed … Jul 24, 2026
CVE-2026-12689 MEDIUM 5.4 The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with … Jul 24, 2026
CVE-2026-12688 MEDIUM 6.5 The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification … Jul 24, 2026
CVE-2026-12497 HIGH 7.5 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role … Jul 24, 2026
CVE-2026-16870 HIGH 8.8 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file … Jul 24, 2026
CVE-2026-66141 HIGH 7.4 Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. Jul 24, 2026
CVE-2026-66140 HIGH 8.4 Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled. Jul 24, 2026
CVE-2026-66139 MEDIUM 4.8 OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. Jul 24, 2026
CVE-2026-66138 HIGH 7.2 In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a … Jul 24, 2026
CVE-2026-54422 MEDIUM 5.5 In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download … Jul 24, 2026
CVE-2026-6454 MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient … Jul 24, 2026