Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52841
Total
4211
Critical
15646
High
15361
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41880 | UNKNOWN | — | R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without proper … | Jul 10, 2026 |
| CVE-2026-41879 | UNKNOWN | — | R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this … | Jul 10, 2026 |
| CVE-2026-41878 | UNKNOWN | — | R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID … | Jul 10, 2026 |
| CVE-2026-41877 | UNKNOWN | — | R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the file … | Jul 10, 2026 |
| CVE-2026-41876 | UNKNOWN | — | R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This … | Jul 10, 2026 |
| CVE-2026-15378 | CRITICAL | 9.3 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a … | Jul 10, 2026 |
| CVE-2026-15028 | LOW | 3.9 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The … | Jul 10, 2026 |
| CVE-2026-13710 | MEDIUM | 6.4 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Jul 10, 2026 |
| CVE-2026-13247 | MEDIUM | 6.4 | The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | Jul 10, 2026 |
| CVE-2026-13010 | MEDIUM | 6.5 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute … | Jul 10, 2026 |
| CVE-2026-12918 | MEDIUM | 4.9 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter … | Jul 10, 2026 |
| CVE-2026-11990 | MEDIUM | 5.3 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. … | Jul 10, 2026 |
| CVE-2026-9838 | MEDIUM | 6.1 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due … | Jul 10, 2026 |
| CVE-2026-6802 | MEDIUM | 5.3 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due … | Jul 10, 2026 |
| CVE-2026-6440 | MEDIUM | 4.3 | The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to … | Jul 10, 2026 |
| CVE-2026-3907 | MEDIUM | 6.4 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is … | Jul 10, 2026 |
| CVE-2026-1946 | MEDIUM | 4.3 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function … | Jul 10, 2026 |
| CVE-2026-15104 | MEDIUM | 6.5 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter … | Jul 10, 2026 |
| CVE-2026-15026 | MEDIUM | 4.3 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via … | Jul 10, 2026 |
| CVE-2026-14475 | MEDIUM | 4.9 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in … | Jul 10, 2026 |
| CVE-2026-12955 | MEDIUM | 4.3 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on … | Jul 10, 2026 |
| CVE-2026-12924 | MEDIUM | 6.4 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter … | Jul 10, 2026 |
| CVE-2026-12400 | MEDIUM | 4.3 | The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via … | Jul 10, 2026 |
| CVE-2026-12108 | MEDIUM | 4.4 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due … | Jul 10, 2026 |
| CVE-2026-11992 | MEDIUM | 4.3 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin … | Jul 10, 2026 |