Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82448 | CRITICAL | 9.8 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching … | Aug 29, 2026 |
| CVE-2026-82447 | HIGH | 8.8 | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed … | Aug 29, 2026 |
| CVE-2026-14494 | CRITICAL | 9.8 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. … | Aug 29, 2026 |
| CVE-2026-82364 | MEDIUM | 4.2 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order … | Aug 29, 2026 |
| CVE-2026-80725 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond … | Aug 29, 2026 |
| CVE-2026-81346 | MEDIUM | 4.3 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, … | Aug 29, 2026 |
| CVE-2026-81342 | MEDIUM | 4.7 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers … | Aug 29, 2026 |
| CVE-2026-81200 | LOW | 2.7 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to … | Aug 29, 2026 |
| CVE-2026-81026 | MEDIUM | 4.8 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the … | Aug 29, 2026 |
| CVE-2026-80488 | MEDIUM | 4.1 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, … | Aug 29, 2026 |
| CVE-2026-80311 | MEDIUM | 4.3 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the … | Aug 29, 2026 |
| CVE-2026-77786 | MEDIUM | 4.9 | The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires … | Aug 29, 2026 |
| CVE-2026-77704 | LOW | 2.7 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change … | Aug 29, 2026 |
| CVE-2026-77012 | CRITICAL | 9.3 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does … | Aug 29, 2026 |
| CVE-2026-77010 | MEDIUM | 6.5 | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently … | Aug 29, 2026 |
| CVE-2026-77008 | MEDIUM | 6.5 | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated … | Aug 29, 2026 |
| CVE-2026-77007 | HIGH | 7.5 | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing … | Aug 29, 2026 |
| CVE-2026-76586 | HIGH | 7.5 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for … | Aug 29, 2026 |
| CVE-2026-76548 | HIGH | 8.2 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. … | Aug 29, 2026 |
| CVE-2026-76547 | MEDIUM | 6.6 | The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege … | Aug 29, 2026 |
| CVE-2026-76546 | MEDIUM | 6.8 | The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as … | Aug 29, 2026 |
| CVE-2026-19430 | MEDIUM | 5.3 | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content … | Aug 29, 2026 |
| CVE-2026-18234 | MEDIUM | 6.5 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does … | Aug 29, 2026 |
| CVE-2026-18233 | MEDIUM | 6.5 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing … | Aug 29, 2026 |
| CVE-2026-17522 | MEDIUM | 5.4 | The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted … | Aug 29, 2026 |