Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51787
Total
4103
Critical
15361
High
15039
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16246 | HIGH | 7.3 | In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over … | Jul 20, 2026 |
| CVE-2026-15813 | MEDIUM | 6.5 | A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence … | Jul 20, 2026 |
| CVE-2026-15588 | MEDIUM | 5.3 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data … | Jul 20, 2026 |
| CVE-2026-14448 | HIGH | 7.2 | An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in … | Jul 20, 2026 |
| CVE-2026-2445 | MEDIUM | 6.1 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows … | Jul 20, 2026 |
| CVE-2026-16242 | CRITICAL | 9.4 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), … | Jul 20, 2026 |
| CVE-2026-13577 | HIGH | 8.2 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id … | Jul 20, 2026 |
| CVE-2026-9833 | HIGH | 7.1 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters … | Jul 20, 2026 |
| CVE-2026-8825 | MEDIUM | 4.9 | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing … | Jul 20, 2026 |
| CVE-2026-6656 | HIGH | 7.5 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to … | Jul 20, 2026 |
| CVE-2026-16235 | CRITICAL | 9.8 | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for … | Jul 20, 2026 |
| CVE-2026-13432 | MEDIUM | 5.4 | The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or … | Jul 20, 2026 |
| CVE-2026-13156 | MEDIUM | 5.4 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), … | Jul 20, 2026 |
| CVE-2026-13147 | CRITICAL | 9.1 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP … | Jul 20, 2026 |
| CVE-2026-13142 | UNKNOWN | — | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its … | Jul 20, 2026 |
| CVE-2026-12973 | MEDIUM | 6.5 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, … | Jul 20, 2026 |
| CVE-2026-12972 | MEDIUM | 5.3 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, … | Jul 20, 2026 |
| CVE-2026-12970 | HIGH | 7.1 | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that … | Jul 20, 2026 |
| CVE-2026-12898 | MEDIUM | 6.5 | The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, … | Jul 20, 2026 |
| CVE-2026-12724 | MEDIUM | 4.3 | The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in … | Jul 20, 2026 |
| CVE-2026-12723 | MEDIUM | 5.3 | The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content … | Jul 20, 2026 |
| CVE-2026-12592 | HIGH | 7.5 | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors … | Jul 20, 2026 |
| CVE-2026-11868 | MEDIUM | 5.3 | The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated … | Jul 20, 2026 |
| CVE-2026-11349 | HIGH | 8.6 | The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter … | Jul 20, 2026 |
| CVE-2026-10755 | LOW | 2.7 | The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users … | Jul 20, 2026 |