Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51667
Total
4097
Critical
15338
High
14987
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15404 | MEDIUM | 6.4 | The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to … | Jul 23, 2026 |
| CVE-2026-15394 | MEDIUM | 6.4 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet … | Jul 23, 2026 |
| CVE-2026-15348 | MEDIUM | 6.3 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via … | Jul 23, 2026 |
| CVE-2026-15017 | HIGH | 8.8 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing … | Jul 23, 2026 |
| CVE-2026-15015 | CRITICAL | 9.8 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is … | Jul 23, 2026 |
| CVE-2026-15011 | CRITICAL | 9.8 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and … | Jul 23, 2026 |
| CVE-2026-14481 | MEDIUM | 6.4 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' … | Jul 23, 2026 |
| CVE-2026-14282 | CRITICAL | 9.8 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary … | Jul 23, 2026 |
| CVE-2026-13119 | MEDIUM | 6.5 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit … | Jul 23, 2026 |
| CVE-2026-13009 | MEDIUM | 6.5 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, … | Jul 23, 2026 |
| CVE-2026-52688 | HIGH | 7.5 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | Jul 23, 2026 |
| CVE-2026-52686 | LOW | 3.7 | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME … | Jul 23, 2026 |
| CVE-2026-52684 | LOW | 3.7 | If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does … | Jul 23, 2026 |
| CVE-2026-16723 | CRITICAL | 9.0 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement … | Jul 23, 2026 |
| CVE-2026-16287 | HIGH | 7.8 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command … | Jul 23, 2026 |
| CVE-2024-58330 | HIGH | 7.5 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. | Jul 23, 2026 |
| CVE-2024-58023 | HIGH | 8.4 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | Jul 23, 2026 |
| CVE-2026-9729 | MEDIUM | 6.4 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, … | Jul 23, 2026 |
| CVE-2026-9713 | HIGH | 7.5 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON … | Jul 23, 2026 |
| CVE-2026-9635 | MEDIUM | 6.4 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up … | Jul 23, 2026 |
| CVE-2026-59678 | UNKNOWN | — | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This … | Jul 23, 2026 |
| CVE-2026-59677 | UNKNOWN | — | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in … | Jul 23, 2026 |
| CVE-2026-12421 | HIGH | 7.2 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to … | Jul 23, 2026 |
| CVE-2026-9577 | MEDIUM | 4.8 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page … | Jul 23, 2026 |
| CVE-2026-9066 | MEDIUM | 6.1 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it … | Jul 23, 2026 |