Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42683
Total
3463
Critical
12701
High
12563
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82111 | MEDIUM | 4.3 | A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. … | Aug 28, 2026 |
| CVE-2026-81777 | MEDIUM | 5.3 | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. | Aug 28, 2026 |
| CVE-2026-81733 | UNKNOWN | — | WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user … | Aug 28, 2026 |
| CVE-2026-81732 | UNKNOWN | — | WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send … | Aug 28, 2026 |
| CVE-2026-78073 | UNKNOWN | — | Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors | Aug 28, 2026 |
| CVE-2026-78072 | UNKNOWN | — | Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 | Aug 28, 2026 |
| CVE-2026-78071 | UNKNOWN | — | Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping … | Aug 28, 2026 |
| CVE-2026-78070 | UNKNOWN | — | Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL … | Aug 28, 2026 |
| CVE-2026-73209 | MEDIUM | 6.5 | An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process … | Aug 28, 2026 |
| CVE-2026-73208 | HIGH | 7.4 | An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, … | Aug 28, 2026 |
| CVE-2026-6128 | MEDIUM | 6.4 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and … | Aug 28, 2026 |
| CVE-2026-5510 | MEDIUM | 6.4 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up … | Aug 28, 2026 |
| CVE-2026-52687 | MEDIUM | 6.5 | An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and … | Aug 28, 2026 |
| CVE-2026-52681 | LOW | 3.1 | Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the … | Aug 28, 2026 |
| CVE-2026-42395 | MEDIUM | 4.3 | A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. … | Aug 28, 2026 |
| CVE-2026-42393 | LOW | 3.1 | The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An … | Aug 28, 2026 |
| CVE-2026-42392 | MEDIUM | 4.3 | An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned … | Aug 28, 2026 |
| CVE-2026-42391 | HIGH | 7.5 | An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage … | Aug 28, 2026 |
| CVE-2026-42008 | MEDIUM | 4.3 | Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by … | Aug 28, 2026 |
| CVE-2026-42007 | CRITICAL | 9.1 | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and … | Aug 28, 2026 |
| CVE-2026-40205 | MEDIUM | 5.9 | An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in … | Aug 28, 2026 |
| CVE-2026-40204 | LOW | 3.1 | None None None No publicly available exploits are known. | Aug 28, 2026 |
| CVE-2026-40203 | LOW | 3.7 | When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and … | Aug 28, 2026 |
| CVE-2026-40019 | MEDIUM | 5.9 | An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This … | Aug 28, 2026 |
| CVE-2026-40018 | HIGH | 7.4 | None None None No publicly available exploits are known. | Aug 28, 2026 |