Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5069 | MEDIUM | 5.4 | The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due … | Jul 10, 2026 |
| CVE-2026-54423 | HIGH | 8.2 | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step … | Jul 10, 2026 |
| CVE-2026-44918 | MEDIUM | 5.5 | OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. | Jul 10, 2026 |
| CVE-2026-15329 | MEDIUM | 4.3 | A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. … | Jul 10, 2026 |
| CVE-2026-15326 | LOW | 3.8 | A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such … | Jul 10, 2026 |
| CVE-2026-15321 | LOW | 2.4 | A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. … | Jul 10, 2026 |
| CVE-2026-15070 | HIGH | 8.8 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This … | Jul 10, 2026 |
| CVE-2026-14894 | CRITICAL | 9.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … | Jul 10, 2026 |
| CVE-2026-13430 | HIGH | 7.2 | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the … | Jul 10, 2026 |
| CVE-2026-11818 | MEDIUM | 5.4 | The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Jul 10, 2026 |
| CVE-2026-11392 | MEDIUM | 6.1 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and … | Jul 10, 2026 |
| CVE-2026-15320 | MEDIUM | 5.4 | A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the … | Jul 10, 2026 |
| CVE-2026-15319 | HIGH | 7.3 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. … | Jul 10, 2026 |
| CVE-2026-15318 | MEDIUM | 6.3 | A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the … | Jul 10, 2026 |
| CVE-2026-55616 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49757. Reason: This candidate is a duplicate of CVE-2026-49757. Notes: All CVE users … | Jul 10, 2026 |
| CVE-2026-55615 | UNKNOWN | — | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, … | Jul 10, 2026 |
| CVE-2026-54771 | HIGH | 8.1 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct … | Jul 10, 2026 |
| CVE-2026-54769 | CRITICAL | 10.0 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) … | Jul 10, 2026 |
| CVE-2026-54760 | UNKNOWN | — | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) … | Jul 10, 2026 |
| CVE-2026-50181 | HIGH | 7.1 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary … | Jul 10, 2026 |
| CVE-2026-50180 | UNKNOWN | — | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS` regex blocklist enumerates … | Jul 10, 2026 |
| CVE-2026-15317 | MEDIUM | 6.3 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of … | Jul 10, 2026 |
| CVE-2026-15311 | LOW | 3.5 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component … | Jul 10, 2026 |
| CVE-2026-12598 | HIGH | 8.1 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This … | Jul 10, 2026 |
| CVE-2026-12597 | HIGH | 8.1 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability … | Jul 10, 2026 |