Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-80595 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - add response length checks The driver processes response data from device buffers … | Aug 28, 2026 |
| CVE-2026-80594 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing The driver parses … | Aug 28, 2026 |
| CVE-2026-80593 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_atk0110) Check package count before accessing element atk_ec_present() walks the management group package returned … | Aug 28, 2026 |
| CVE-2026-80592 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: fail early if address range parameters are invalid The comment on top of `struct … | Aug 28, 2026 |
| CVE-2026-80591 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its … | Aug 28, 2026 |
| CVE-2026-80590 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with … | Aug 28, 2026 |
| CVE-2026-79996 | HIGH | 7.2 | The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have … | Aug 28, 2026 |
| CVE-2026-79995 | MEDIUM | 4.3 | The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the … | Aug 28, 2026 |
| CVE-2026-79706 | MEDIUM | 5.3 | The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the … | Aug 28, 2026 |
| CVE-2026-79615 | LOW | 2.7 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API … | Aug 28, 2026 |
| CVE-2026-78238 | MEDIUM | 5.4 | SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … | Aug 28, 2026 |
| CVE-2026-78032 | CRITICAL | 9.8 | SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege. | Aug 28, 2026 |
| CVE-2026-77838 | MEDIUM | 5.4 | SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … | Aug 28, 2026 |
| CVE-2026-77701 | MEDIUM | 5.3 | The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create … | Aug 28, 2026 |
| CVE-2026-76581 | CRITICAL | 9.8 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent … | Aug 28, 2026 |
| CVE-2026-73827 | MEDIUM | 5.4 | SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to … | Aug 28, 2026 |
| CVE-2026-6286 | HIGH | 7.2 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up … | Aug 28, 2026 |
| CVE-2026-5097 | HIGH | 7.5 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is … | Aug 28, 2026 |
| CVE-2026-4246 | MEDIUM | 6.1 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions … | Aug 28, 2026 |
| CVE-2026-40541 | CRITICAL | 9.0 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, … | Aug 28, 2026 |
| CVE-2026-19423 | HIGH | 8.1 | The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form … | Aug 28, 2026 |
| CVE-2026-19084 | HIGH | 7.5 | The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files … | Aug 28, 2026 |
| CVE-2026-14567 | MEDIUM | 5.3 | The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address … | Aug 28, 2026 |
| CVE-2026-14558 | HIGH | 7.2 | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users … | Aug 28, 2026 |
| CVE-2026-12514 | MEDIUM | 5.3 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered … | Aug 28, 2026 |