Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15380 | UNKNOWN | — | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS … | Jul 17, 2026 |
| CVE-2026-15379 | UNKNOWN | — | The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM … | Jul 17, 2026 |
| CVE-2026-9810 | CRITICAL | 9.8 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator … | Jul 17, 2026 |
| CVE-2026-13402 | MEDIUM | 5.3 | The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one … | Jul 17, 2026 |
| CVE-2026-12393 | MEDIUM | 5.4 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing … | Jul 17, 2026 |
| CVE-2026-11966 | MEDIUM | 5.3 | The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions … | Jul 17, 2026 |
| CVE-2026-11961 | HIGH | 8.1 | The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers … | Jul 17, 2026 |
| CVE-2026-11575 | HIGH | 7.5 | The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback … | Jul 17, 2026 |
| CVE-2026-10525 | MEDIUM | 6.1 | The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin … | Jul 17, 2026 |
| CVE-2019-25764 | UNKNOWN | — | **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and … | Jul 17, 2026 |
| CVE-2026-15982 | CRITICAL | 9.8 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up … | Jul 17, 2026 |
| CVE-2026-15094 | MEDIUM | 6.1 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 … | Jul 17, 2026 |
| CVE-2026-60060 | MEDIUM | 6.3 | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish … | Jul 17, 2026 |
| CVE-2026-58317 | MEDIUM | 6.3 | Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an … | Jul 17, 2026 |
| CVE-2026-41993 | MEDIUM | 4.4 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file … | Jul 17, 2026 |
| CVE-2026-21770 | MEDIUM | 6.5 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with … | Jul 17, 2026 |
| CVE-2026-15759 | MEDIUM | 6.4 | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Jul 17, 2026 |
| CVE-2026-15457 | MEDIUM | 4.9 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … | Jul 17, 2026 |
| CVE-2026-15349 | MEDIUM | 4.3 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … | Jul 17, 2026 |
| CVE-2026-15161 | MEDIUM | 6.4 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due … | Jul 17, 2026 |
| CVE-2026-14503 | MEDIUM | 6.5 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This … | Jul 17, 2026 |
| CVE-2026-13765 | HIGH | 7.5 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … | Jul 17, 2026 |
| CVE-2026-13352 | HIGH | 8.8 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File … | Jul 17, 2026 |
| CVE-2026-8616 | MEDIUM | 5.3 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce … | Jul 17, 2026 |
| CVE-2026-15395 | HIGH | 7.2 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions … | Jul 17, 2026 |