Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-17520 | MEDIUM | 4.8 | The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing … | Aug 29, 2026 |
| CVE-2026-16947 | CRITICAL | 9.1 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification … | Aug 29, 2026 |
| CVE-2026-16600 | HIGH | 7.7 | The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL … | Aug 29, 2026 |
| CVE-2026-16259 | CRITICAL | 9.8 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and … | Aug 29, 2026 |
| CVE-2026-16061 | HIGH | 8.6 | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes … | Aug 29, 2026 |
| CVE-2026-10522 | UNKNOWN | — | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register … | Aug 29, 2026 |
| CVE-2026-41012 | HIGH | 7.7 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials … | Aug 29, 2026 |
| CVE-2026-55867 | UNKNOWN | — | Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java … | Aug 28, 2026 |
| CVE-2026-55860 | MEDIUM | 5.9 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport … | Aug 28, 2026 |
| CVE-2026-55859 | MEDIUM | 5.9 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption … | Aug 28, 2026 |
| CVE-2026-55858 | MEDIUM | 5.9 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes … | Aug 28, 2026 |
| CVE-2026-55857 | MEDIUM | 5.9 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication … | Aug 28, 2026 |
| CVE-2026-55856 | MEDIUM | 5.9 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java … | Aug 28, 2026 |
| CVE-2026-55855 | MEDIUM | 6.5 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits … | Aug 28, 2026 |
| CVE-2026-55854 | MEDIUM | 5.9 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can … | Aug 28, 2026 |
| CVE-2026-55848 | HIGH | 8.6 | mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML … | Aug 28, 2026 |
| CVE-2026-55841 | HIGH | 7.5 | Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate … | Aug 28, 2026 |
| CVE-2026-55785 | LOW | 3.7 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality … | Aug 28, 2026 |
| CVE-2026-55784 | HIGH | 7.5 | free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global … | Aug 28, 2026 |
| CVE-2026-55779 | MEDIUM | 5.4 | Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), … | Aug 28, 2026 |
| CVE-2026-55764 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on … | Aug 28, 2026 |
| CVE-2026-82333 | HIGH | 7.5 | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser … | Aug 28, 2026 |
| CVE-2026-82018 | MEDIUM | 6.1 | IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that … | Aug 28, 2026 |
| CVE-2026-82017 | HIGH | 7.6 | IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to … | Aug 28, 2026 |
| CVE-2026-81533 | HIGH | 7.1 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of … | Aug 28, 2026 |