Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42683
Total
3463
Critical
12701
High
12563
Medium
CVE ID Severity Score Description Published
CVE-2026-82328 MEDIUM 6.1 A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the … Aug 28, 2026
CVE-2026-82327 MEDIUM 5.5 A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache … Aug 28, 2026
CVE-2026-82324 MEDIUM 6.1 A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate … Aug 28, 2026
CVE-2026-82227 HIGH 8.5 Contributor SQL Injection in WPBulky <= 1.2.2 versions. Aug 28, 2026
CVE-2026-82220 MEDIUM 5.3 Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. Aug 28, 2026
CVE-2026-82181 MEDIUM 5.5 Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history … Aug 28, 2026
CVE-2026-82112 LOW 3.5 A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component … Aug 28, 2026
CVE-2026-82078 UNKNOWN An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based … Aug 28, 2026
CVE-2026-81767 HIGH 7.5 Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. Aug 28, 2026
CVE-2026-81761 MEDIUM 4.3 Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. Aug 28, 2026
CVE-2026-81760 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. Aug 28, 2026
CVE-2026-81759 MEDIUM 5.4 Contributor Broken Access Control in WpEvently <= 5.5.0 versions. Aug 28, 2026
CVE-2026-81757 HIGH 7.2 Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. Aug 28, 2026
CVE-2026-81578 UNKNOWN An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative … Aug 28, 2026
CVE-2026-81341 MEDIUM 6.5 wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence … Aug 28, 2026
CVE-2026-81299 MEDIUM 4.3 Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. Aug 28, 2026
CVE-2026-81285 HIGH 7.5 Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. Aug 28, 2026
CVE-2026-81284 MEDIUM 4.3 Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. Aug 28, 2026
CVE-2026-81020 HIGH 7.4 wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … Aug 28, 2026
CVE-2026-81019 HIGH 7.4 wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a … Aug 28, 2026
CVE-2026-75758 UNKNOWN Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM … Aug 28, 2026
CVE-2026-6176 HIGH 7.2 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and … Aug 28, 2026
CVE-2026-5953 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: … Aug 28, 2026
CVE-2026-5934 HIGH 7.2 The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input … Aug 28, 2026
CVE-2026-5800 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue … Aug 28, 2026