Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12513 | MEDIUM | 6.8 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission … | Aug 28, 2026 |
| CVE-2026-82090 | UNKNOWN | — | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge … | Aug 28, 2026 |
| CVE-2026-82089 | UNKNOWN | — | The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView. | Aug 28, 2026 |
| CVE-2026-82082 | CRITICAL | 9.8 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | Aug 28, 2026 |
| CVE-2026-82081 | MEDIUM | 6.4 | wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export. | Aug 28, 2026 |
| CVE-2026-77365 | HIGH | 7.2 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored … | Aug 28, 2026 |
| CVE-2026-76053 | HIGH | 7.2 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser … | Aug 28, 2026 |
| CVE-2026-3129 | MEDIUM | 6.4 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. … | Aug 28, 2026 |
| CVE-2026-18983 | HIGH | 7.5 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 … | Aug 28, 2026 |
| CVE-2026-18978 | HIGH | 7.2 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to … | Aug 28, 2026 |
| CVE-2026-18324 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field … | Aug 28, 2026 |
| CVE-2026-16759 | MEDIUM | 6.5 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all … | Aug 28, 2026 |
| CVE-2026-16654 | MEDIUM | 6.4 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 … | Aug 28, 2026 |
| CVE-2026-15798 | MEDIUM | 6.4 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 … | Aug 28, 2026 |
| CVE-2026-78618 | UNKNOWN | — | A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially … | Aug 28, 2026 |
| CVE-2026-78617 | UNKNOWN | — | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against … | Aug 28, 2026 |
| CVE-2026-78616 | UNKNOWN | — | A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's … | Aug 28, 2026 |
| CVE-2026-78615 | UNKNOWN | — | A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with … | Aug 28, 2026 |
| CVE-2026-78614 | UNKNOWN | — | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command … | Aug 28, 2026 |
| CVE-2026-78613 | UNKNOWN | — | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command … | Aug 28, 2026 |
| CVE-2026-78612 | UNKNOWN | — | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command … | Aug 28, 2026 |
| CVE-2026-78610 | UNKNOWN | — | WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to … | Aug 28, 2026 |
| CVE-2026-78500 | UNKNOWN | — | A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent … | Aug 28, 2026 |
| CVE-2026-78499 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network … | Aug 28, 2026 |
| CVE-2026-78498 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network … | Aug 28, 2026 |