Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
31378
Total
2488
Critical
9260
High
9611
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-30993 | CRITICAL | 9.8 | Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable … | Apr 15, 2026 |
| CVE-2026-6372 | HIGH | 7.5 | Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a … | Apr 15, 2026 |
| CVE-2026-6370 | MEDIUM | 5.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Ajax Cart for WooCommerce allows Stored XSS.This issue affects Mini Ajax … | Apr 15, 2026 |
| CVE-2026-30996 | HIGH | 7.5 | An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files … | Apr 15, 2026 |
| CVE-2026-30995 | HIGH | 8.6 | Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint. | Apr 15, 2026 |
| CVE-2026-30994 | HIGH | 7.5 | Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials. | Apr 15, 2026 |
| CVE-2026-20186 | CRITICAL | 9.9 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an … | Apr 15, 2026 |
| CVE-2026-20184 | CRITICAL | 9.8 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate … | Apr 15, 2026 |
| CVE-2026-20180 | CRITICAL | 9.9 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an … | Apr 15, 2026 |
| CVE-2026-20170 | MEDIUM | 6.1 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco … | Apr 15, 2026 |
| CVE-2026-20161 | MEDIUM | 5.5 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the … | Apr 15, 2026 |
| CVE-2026-20152 | MEDIUM | 5.3 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication … | Apr 15, 2026 |
| CVE-2026-20148 | MEDIUM | 4.9 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and … | Apr 15, 2026 |
| CVE-2026-20147 | CRITICAL | 9.9 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an … | Apr 15, 2026 |
| CVE-2026-20136 | MEDIUM | 6.0 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative … | Apr 15, 2026 |
| CVE-2026-20132 | MEDIUM | 4.8 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a … | Apr 15, 2026 |
| CVE-2026-20081 | MEDIUM | 6.5 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker … | Apr 15, 2026 |
| CVE-2026-20078 | MEDIUM | 6.5 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker … | Apr 15, 2026 |
| CVE-2026-20061 | MEDIUM | 4.3 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an … | Apr 15, 2026 |
| CVE-2026-20060 | MEDIUM | 4.7 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web … | Apr 15, 2026 |
| CVE-2026-20059 | MEDIUM | 6.1 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a … | Apr 15, 2026 |
| CVE-2025-63029 | HIGH | 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace allows SQL Injection.This issue affects WCFM Marketplace: … | Apr 15, 2026 |
| CVE-2025-15636 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through … | Apr 15, 2026 |
| CVE-2025-15635 | MEDIUM | 4.3 | Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from … | Apr 15, 2026 |
| CVE-2025-15610 | UNKNOWN | — | Deserialization of untrusted data vulnerability in OpenText, Inc RightFax on Windows, 64 bit, 32 bit allows Object Injection.This issue affects RightFax: through 25.4. | Apr 15, 2026 |