Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42400
Total
3455
Critical
12534
High
12466
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81767 | HIGH | 7.5 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | Aug 28, 2026 |
| CVE-2026-81761 | MEDIUM | 4.3 | Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | Aug 28, 2026 |
| CVE-2026-81760 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | Aug 28, 2026 |
| CVE-2026-81759 | MEDIUM | 5.4 | Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | Aug 28, 2026 |
| CVE-2026-81757 | HIGH | 7.2 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | Aug 28, 2026 |
| CVE-2026-81578 | UNKNOWN | — | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative … | Aug 28, 2026 |
| CVE-2026-81341 | MEDIUM | 6.5 | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence … | Aug 28, 2026 |
| CVE-2026-81299 | MEDIUM | 4.3 | Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | Aug 28, 2026 |
| CVE-2026-81285 | HIGH | 7.5 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | Aug 28, 2026 |
| CVE-2026-81284 | MEDIUM | 4.3 | Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | Aug 28, 2026 |
| CVE-2026-81020 | HIGH | 7.4 | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … | Aug 28, 2026 |
| CVE-2026-81019 | HIGH | 7.4 | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … | Aug 28, 2026 |
| CVE-2026-75758 | UNKNOWN | — | Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM … | Aug 28, 2026 |
| CVE-2026-6176 | HIGH | 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and … | Aug 28, 2026 |
| CVE-2026-5953 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: … | Aug 28, 2026 |
| CVE-2026-5934 | HIGH | 7.2 | The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input … | Aug 28, 2026 |
| CVE-2026-5800 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue … | Aug 28, 2026 |
| CVE-2026-5096 | MEDIUM | 5.3 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the … | Aug 28, 2026 |
| CVE-2026-58107 | UNKNOWN | — | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store … | Aug 28, 2026 |
| CVE-2026-58106 | UNKNOWN | — | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, … | Aug 28, 2026 |
| CVE-2026-56854 | HIGH | 7.5 | The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for … | Aug 28, 2026 |
| CVE-2026-50979 | HIGH | 8.1 | A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the … | Aug 28, 2026 |
| CVE-2026-4378 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects … | Aug 28, 2026 |
| CVE-2026-3423 | MEDIUM | 6.4 | The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, … | Aug 28, 2026 |
| CVE-2026-38725 | MEDIUM | 5.4 | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input … | Aug 28, 2026 |