Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81660 | UNKNOWN | — | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields … | Aug 30, 2026 |
| CVE-2026-78364 | UNKNOWN | — | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin … | Aug 30, 2026 |
| CVE-2026-76585 | UNKNOWN | — | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, … | Aug 30, 2026 |
| CVE-2026-19722 | UNKNOWN | — | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, … | Aug 30, 2026 |
| CVE-2026-14835 | UNKNOWN | — | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from … | Aug 30, 2026 |
| CVE-2026-14307 | UNKNOWN | — | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an … | Aug 30, 2026 |
| CVE-2026-82480 | HIGH | 7.4 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the … | Aug 30, 2026 |
| CVE-2026-82479 | MEDIUM | 6.3 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. … | Aug 30, 2026 |
| CVE-2026-82478 | HIGH | 7.3 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This … | Aug 30, 2026 |
| CVE-2026-15980 | CRITICAL | 9.8 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization … | Aug 30, 2026 |
| CVE-2026-77846 | UNKNOWN | — | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested … | Aug 30, 2026 |
| CVE-2026-75759 | UNKNOWN | — | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM … | Aug 30, 2026 |
| CVE-2026-82562 | LOW | 3.7 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array … | Aug 30, 2026 |
| CVE-2026-77970 | UNKNOWN | — | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested … | Aug 30, 2026 |
| CVE-2026-77831 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to … | Aug 30, 2026 |
| CVE-2026-75847 | UNKNOWN | — | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of … | Aug 30, 2026 |
| CVE-2026-82417 | MEDIUM | 5.3 | ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by … | Aug 30, 2026 |
| CVE-2026-82424 | MEDIUM | 6.3 | A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a … | Aug 29, 2026 |
| CVE-2026-82423 | MEDIUM | 5.4 | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component … | Aug 29, 2026 |
| CVE-2026-82422 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of … | Aug 29, 2026 |
| CVE-2026-82421 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the … | Aug 29, 2026 |
| CVE-2026-15369 | CRITICAL | 9.8 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due … | Aug 29, 2026 |
| CVE-2026-75807 | HIGH | 7.5 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is … | Aug 29, 2026 |
| CVE-2026-82476 | MEDIUM | 5.3 | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers … | Aug 29, 2026 |
| CVE-2026-82475 | HIGH | 8.1 | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers … | Aug 29, 2026 |