Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51667
Total
4097
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-15404 MEDIUM 6.4 The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to … Jul 23, 2026
CVE-2026-15394 MEDIUM 6.4 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet … Jul 23, 2026
CVE-2026-15348 MEDIUM 6.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via … Jul 23, 2026
CVE-2026-15017 HIGH 8.8 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing … Jul 23, 2026
CVE-2026-15015 CRITICAL 9.8 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is … Jul 23, 2026
CVE-2026-15011 CRITICAL 9.8 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and … Jul 23, 2026
CVE-2026-14481 MEDIUM 6.4 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' … Jul 23, 2026
CVE-2026-14282 CRITICAL 9.8 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary … Jul 23, 2026
CVE-2026-13119 MEDIUM 6.5 The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit … Jul 23, 2026
CVE-2026-13009 MEDIUM 6.5 The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, … Jul 23, 2026
CVE-2026-52688 HIGH 7.5 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation Jul 23, 2026
CVE-2026-52686 LOW 3.7 The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME … Jul 23, 2026
CVE-2026-52684 LOW 3.7 If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does … Jul 23, 2026
CVE-2026-16723 CRITICAL 9.0 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement … Jul 23, 2026
CVE-2026-16287 HIGH 7.8 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command … Jul 23, 2026
CVE-2024-58330 HIGH 7.5 A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. Jul 23, 2026
CVE-2024-58023 HIGH 8.4 Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. Jul 23, 2026
CVE-2026-9729 MEDIUM 6.4 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, … Jul 23, 2026
CVE-2026-9713 HIGH 7.5 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON … Jul 23, 2026
CVE-2026-9635 MEDIUM 6.4 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up … Jul 23, 2026
CVE-2026-59678 UNKNOWN — An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This … Jul 23, 2026
CVE-2026-59677 UNKNOWN — A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in … Jul 23, 2026
CVE-2026-12421 HIGH 7.2 The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to … Jul 23, 2026
CVE-2026-9577 MEDIUM 4.8 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page … Jul 23, 2026
CVE-2026-9066 MEDIUM 6.1 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it … Jul 23, 2026