Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42739
Total
3465
Critical
12744
High
12574
Medium
CVE ID Severity Score Description Published
CVE-2026-80595 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - add response length checks The driver processes response data from device buffers … Aug 28, 2026
CVE-2026-80594 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing The driver parses … Aug 28, 2026
CVE-2026-80593 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_atk0110) Check package count before accessing element atk_ec_present() walks the management group package returned … Aug 28, 2026
CVE-2026-80592 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: fail early if address range parameters are invalid The comment on top of `struct … Aug 28, 2026
CVE-2026-80591 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its … Aug 28, 2026
CVE-2026-80590 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with … Aug 28, 2026
CVE-2026-79996 HIGH 7.2 The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have … Aug 28, 2026
CVE-2026-79995 MEDIUM 4.3 The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the … Aug 28, 2026
CVE-2026-79706 MEDIUM 5.3 The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the … Aug 28, 2026
CVE-2026-79615 LOW 2.7 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API … Aug 28, 2026
CVE-2026-78238 MEDIUM 5.4 SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … Aug 28, 2026
CVE-2026-78032 CRITICAL 9.8 SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. Aug 28, 2026
CVE-2026-77838 MEDIUM 5.4 SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … Aug 28, 2026
CVE-2026-77701 MEDIUM 5.3 The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create … Aug 28, 2026
CVE-2026-76581 CRITICAL 9.8 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent … Aug 28, 2026
CVE-2026-73827 MEDIUM 5.4 SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … Aug 28, 2026
CVE-2026-6286 HIGH 7.2 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up … Aug 28, 2026
CVE-2026-5097 HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is … Aug 28, 2026
CVE-2026-4246 MEDIUM 6.1 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions … Aug 28, 2026
CVE-2026-40541 CRITICAL 9.0 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, … Aug 28, 2026
CVE-2026-19423 HIGH 8.1 The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form … Aug 28, 2026
CVE-2026-19084 HIGH 7.5 The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files … Aug 28, 2026
CVE-2026-14567 MEDIUM 5.3 The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address … Aug 28, 2026
CVE-2026-14558 HIGH 7.2 The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users … Aug 28, 2026
CVE-2026-12514 MEDIUM 5.3 The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered … Aug 28, 2026