Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42275
Total
3446
Critical
12492
High
12441
Medium
CVE ID Severity Score Description Published
CVE-2026-81660 UNKNOWN The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields … Aug 30, 2026
CVE-2026-78364 UNKNOWN The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin … Aug 30, 2026
CVE-2026-76585 UNKNOWN The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, … Aug 30, 2026
CVE-2026-19722 UNKNOWN The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, … Aug 30, 2026
CVE-2026-14835 UNKNOWN The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from … Aug 30, 2026
CVE-2026-14307 UNKNOWN The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an … Aug 30, 2026
CVE-2026-82480 HIGH 7.4 A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the … Aug 30, 2026
CVE-2026-82479 MEDIUM 6.3 A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. … Aug 30, 2026
CVE-2026-82478 HIGH 7.3 A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This … Aug 30, 2026
CVE-2026-15980 CRITICAL 9.8 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization … Aug 30, 2026
CVE-2026-77846 UNKNOWN Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested … Aug 30, 2026
CVE-2026-75759 UNKNOWN Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM … Aug 30, 2026
CVE-2026-82562 LOW 3.7 ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array … Aug 30, 2026
CVE-2026-77970 UNKNOWN Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested … Aug 30, 2026
CVE-2026-77831 UNKNOWN Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to … Aug 30, 2026
CVE-2026-75847 UNKNOWN Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of … Aug 30, 2026
CVE-2026-82417 MEDIUM 5.3 ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by … Aug 30, 2026
CVE-2026-82424 MEDIUM 6.3 A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a … Aug 29, 2026
CVE-2026-82423 MEDIUM 5.4 A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component … Aug 29, 2026
CVE-2026-82422 MEDIUM 6.3 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of … Aug 29, 2026
CVE-2026-82421 MEDIUM 6.3 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the … Aug 29, 2026
CVE-2026-15369 CRITICAL 9.8 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due … Aug 29, 2026
CVE-2026-75807 HIGH 7.5 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is … Aug 29, 2026
CVE-2026-82476 MEDIUM 5.3 Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers … Aug 29, 2026
CVE-2026-82475 HIGH 8.1 iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers … Aug 29, 2026