Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-16247 HIGH 7.3 In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting … Jul 20, 2026
CVE-2026-16246 HIGH 7.3 In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over … Jul 20, 2026
CVE-2026-15813 MEDIUM 6.5 A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence … Jul 20, 2026
CVE-2026-15588 MEDIUM 5.3 A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data … Jul 20, 2026
CVE-2026-14448 HIGH 7.2 An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in … Jul 20, 2026
CVE-2026-2445 MEDIUM 6.1 The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows … Jul 20, 2026
CVE-2026-16242 CRITICAL 9.4 A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), … Jul 20, 2026
CVE-2026-13577 HIGH 8.2 Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id … Jul 20, 2026
CVE-2026-9833 HIGH 7.1 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters … Jul 20, 2026
CVE-2026-8825 MEDIUM 4.9 The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing … Jul 20, 2026
CVE-2026-6656 HIGH 7.5 Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to … Jul 20, 2026
CVE-2026-16235 CRITICAL 9.8 Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for … Jul 20, 2026
CVE-2026-13432 MEDIUM 5.4 The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or … Jul 20, 2026
CVE-2026-13156 MEDIUM 5.4 The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), … Jul 20, 2026
CVE-2026-13147 CRITICAL 9.1 The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP … Jul 20, 2026
CVE-2026-13142 UNKNOWN — The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its … Jul 20, 2026
CVE-2026-12973 MEDIUM 6.5 The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, … Jul 20, 2026
CVE-2026-12972 MEDIUM 5.3 The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, … Jul 20, 2026
CVE-2026-12970 HIGH 7.1 The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that … Jul 20, 2026
CVE-2026-12898 MEDIUM 6.5 The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, … Jul 20, 2026
CVE-2026-12724 MEDIUM 4.3 The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in … Jul 20, 2026
CVE-2026-12723 MEDIUM 5.3 The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content … Jul 20, 2026
CVE-2026-12592 HIGH 7.5 The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors … Jul 20, 2026
CVE-2026-11868 MEDIUM 5.3 The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated … Jul 20, 2026
CVE-2026-11349 HIGH 8.6 The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter … Jul 20, 2026