Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

53238
Total
4231
Critical
15843
High
15500
Medium
CVE ID Severity Score Description Published
CVE-2026-5069 MEDIUM 5.4 The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due … Jul 10, 2026
CVE-2026-54423 HIGH 8.2 In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step … Jul 10, 2026
CVE-2026-44918 MEDIUM 5.5 OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. Jul 10, 2026
CVE-2026-15329 MEDIUM 4.3 A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. … Jul 10, 2026
CVE-2026-15326 LOW 3.8 A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such … Jul 10, 2026
CVE-2026-15321 LOW 2.4 A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. … Jul 10, 2026
CVE-2026-15070 HIGH 8.8 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This … Jul 10, 2026
CVE-2026-14894 CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … Jul 10, 2026
CVE-2026-13430 HIGH 7.2 The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the … Jul 10, 2026
CVE-2026-11818 MEDIUM 5.4 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Jul 10, 2026
CVE-2026-11392 MEDIUM 6.1 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and … Jul 10, 2026
CVE-2026-15320 MEDIUM 5.4 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the … Jul 10, 2026
CVE-2026-15319 HIGH 7.3 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. … Jul 10, 2026
CVE-2026-15318 MEDIUM 6.3 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the … Jul 10, 2026
CVE-2026-55616 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49757. Reason: This candidate is a duplicate of CVE-2026-49757. Notes: All CVE users … Jul 10, 2026
CVE-2026-55615 UNKNOWN — Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, … Jul 10, 2026
CVE-2026-54771 HIGH 8.1 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct … Jul 10, 2026
CVE-2026-54769 CRITICAL 10.0 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) … Jul 10, 2026
CVE-2026-54760 UNKNOWN — Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) … Jul 10, 2026
CVE-2026-50181 HIGH 7.1 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary … Jul 10, 2026
CVE-2026-50180 UNKNOWN — Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS` regex blocklist enumerates … Jul 10, 2026
CVE-2026-15317 MEDIUM 6.3 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of … Jul 10, 2026
CVE-2026-15311 LOW 3.5 A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component … Jul 10, 2026
CVE-2026-12598 HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This … Jul 10, 2026
CVE-2026-12597 HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability … Jul 10, 2026