Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-1372 MEDIUM 4.3 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to … Jul 21, 2026
CVE-2026-15370 MEDIUM 6.7 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When … Jul 21, 2026
CVE-2026-15145 MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in … Jul 21, 2026
CVE-2026-8593 UNKNOWN — Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and … Jul 21, 2026
CVE-2026-3183 HIGH 7.1 Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. Jul 21, 2026
CVE-2026-8082 HIGH 7.5 The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated … Jul 21, 2026
CVE-2026-14185 MEDIUM 4.3 The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with … Jul 21, 2026
CVE-2026-14184 MEDIUM 5.4 The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated … Jul 21, 2026
CVE-2026-14183 MEDIUM 4.3 The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated … Jul 21, 2026
CVE-2026-13694 MEDIUM 6.5 The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger … Jul 21, 2026
CVE-2026-13693 MEDIUM 5.9 The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it … Jul 21, 2026
CVE-2026-11767 HIGH 8.8 The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the … Jul 21, 2026
CVE-2026-3182 MEDIUM 4.3 Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. Jul 21, 2026
CVE-2026-16266 MEDIUM 4.0 Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype … Jul 21, 2026
CVE-2026-15927 MEDIUM 6.8 A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF … Jul 21, 2026
CVE-2026-15812 MEDIUM 4.8 A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to … Jul 21, 2026
CVE-2026-15811 MEDIUM 5.8 A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes … Jul 21, 2026
CVE-2026-15782 MEDIUM 4.9 The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored … Jul 21, 2026
CVE-2026-13439 CRITICAL 9.8 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This … Jul 21, 2026
CVE-2023-37507 UNKNOWN — HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. Jul 21, 2026
CVE-2026-15156 MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color … Jul 21, 2026
CVE-2023-37508 UNKNOWN — HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present. Jul 21, 2026
CVE-2026-59776 MEDIUM 6.8 Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the … Jul 21, 2026
CVE-2026-16336 MEDIUM 4.3 A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of … Jul 21, 2026
CVE-2026-6952 HIGH 7.2 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker … Jul 21, 2026