Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52671
Total
4197
Critical
15603
High
15291
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12081 | MEDIUM | 5.0 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field … | Jul 13, 2026 |
| CVE-2026-11964 | CRITICAL | 9.1 | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated … | Jul 13, 2026 |
| CVE-2026-11963 | HIGH | 8.1 | The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify … | Jul 13, 2026 |
| CVE-2026-10551 | MEDIUM | 6.1 | The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML … | Jul 13, 2026 |
| CVE-2026-15535 | MEDIUM | 6.3 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component … | Jul 13, 2026 |
| CVE-2026-15533 | MEDIUM | 4.7 | A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a … | Jul 13, 2026 |
| CVE-2026-15532 | LOW | 2.4 | A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation … | Jul 13, 2026 |
| CVE-2026-15531 | MEDIUM | 5.3 | A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the … | Jul 13, 2026 |
| CVE-2026-15530 | MEDIUM | 5.3 | A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component … | Jul 13, 2026 |
| CVE-2026-9492 | HIGH | 7.8 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can … | Jul 13, 2026 |
| CVE-2026-7162 | HIGH | 7.8 | Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software. | Jul 13, 2026 |
| CVE-2026-15553 | MEDIUM | 5.3 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for … | Jul 13, 2026 |
| CVE-2026-15552 | MEDIUM | 6.1 | Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers … | Jul 13, 2026 |
| CVE-2026-15529 | MEDIUM | 6.3 | A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results … | Jul 13, 2026 |
| CVE-2026-15528 | LOW | 3.3 | A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the … | Jul 13, 2026 |
| CVE-2026-15527 | MEDIUM | 5.3 | A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument … | Jul 13, 2026 |
| CVE-2026-15526 | LOW | 3.3 | A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component scan_project_deps. Executing a … | Jul 13, 2026 |
| CVE-2026-15525 | MEDIUM | 6.3 | A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the … | Jul 13, 2026 |
| CVE-2026-15524 | LOW | 3.3 | A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Such manipulation of the … | Jul 13, 2026 |
| CVE-2026-15523 | MEDIUM | 6.3 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. … | Jul 13, 2026 |
| CVE-2026-15522 | MEDIUM | 5.3 | A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component … | Jul 13, 2026 |
| CVE-2026-15521 | MEDIUM | 5.3 | A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation … | Jul 13, 2026 |
| CVE-2026-15520 | MEDIUM | 5.3 | A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a … | Jul 13, 2026 |
| CVE-2026-15519 | MEDIUM | 5.0 | A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing … | Jul 13, 2026 |
| CVE-2026-15551 | MEDIUM | 5.5 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects . | Jul 13, 2026 |