Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42683
Total
3463
Critical
12701
High
12563
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82328 | MEDIUM | 6.1 | A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the … | Aug 28, 2026 |
| CVE-2026-82327 | MEDIUM | 5.5 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache … | Aug 28, 2026 |
| CVE-2026-82324 | MEDIUM | 6.1 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate … | Aug 28, 2026 |
| CVE-2026-82227 | HIGH | 8.5 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | Aug 28, 2026 |
| CVE-2026-82220 | MEDIUM | 5.3 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | Aug 28, 2026 |
| CVE-2026-82181 | MEDIUM | 5.5 | Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history … | Aug 28, 2026 |
| CVE-2026-82112 | LOW | 3.5 | A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component … | Aug 28, 2026 |
| CVE-2026-82078 | UNKNOWN | — | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based … | Aug 28, 2026 |
| CVE-2026-81767 | HIGH | 7.5 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | Aug 28, 2026 |
| CVE-2026-81761 | MEDIUM | 4.3 | Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | Aug 28, 2026 |
| CVE-2026-81760 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | Aug 28, 2026 |
| CVE-2026-81759 | MEDIUM | 5.4 | Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | Aug 28, 2026 |
| CVE-2026-81757 | HIGH | 7.2 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | Aug 28, 2026 |
| CVE-2026-81578 | UNKNOWN | — | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative … | Aug 28, 2026 |
| CVE-2026-81341 | MEDIUM | 6.5 | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence … | Aug 28, 2026 |
| CVE-2026-81299 | MEDIUM | 4.3 | Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | Aug 28, 2026 |
| CVE-2026-81285 | HIGH | 7.5 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | Aug 28, 2026 |
| CVE-2026-81284 | MEDIUM | 4.3 | Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | Aug 28, 2026 |
| CVE-2026-81020 | HIGH | 7.4 | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … | Aug 28, 2026 |
| CVE-2026-81019 | HIGH | 7.4 | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … | Aug 28, 2026 |
| CVE-2026-75758 | UNKNOWN | — | Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM … | Aug 28, 2026 |
| CVE-2026-6176 | HIGH | 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and … | Aug 28, 2026 |
| CVE-2026-5953 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: … | Aug 28, 2026 |
| CVE-2026-5934 | HIGH | 7.2 | The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input … | Aug 28, 2026 |
| CVE-2026-5800 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue … | Aug 28, 2026 |