Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42900
Total
3476
Critical
12865
High
12603
Medium
CVE ID Severity Score Description Published
CVE-2026-75005 UNKNOWN Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count … Aug 27, 2026
CVE-2026-74848 UNKNOWN Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on … Aug 27, 2026
CVE-2026-59355 MEDIUM 6.1 In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request … Aug 27, 2026
CVE-2026-59354 CRITICAL 9.6 In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation … Aug 27, 2026
CVE-2026-32566 CRITICAL 9.8 Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 27, 2026
CVE-2026-32564 HIGH 8.5 Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 27, 2026
CVE-2026-32550 HIGH 8.5 Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. Aug 27, 2026
CVE-2026-32479 CRITICAL 9.3 Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. Aug 27, 2026
CVE-2026-27330 HIGH 8.6 Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. Aug 27, 2026
CVE-2026-78333 HIGH 8.8 The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its … Aug 27, 2026
CVE-2026-78139 MEDIUM 4.3 The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all … Aug 27, 2026
CVE-2026-78138 MEDIUM 4.3 The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary … Aug 27, 2026
CVE-2026-78137 HIGH 7.5 The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a … Aug 27, 2026
CVE-2026-78125 MEDIUM 5.3 The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, … Aug 27, 2026
CVE-2026-77991 UNKNOWN Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file … Aug 27, 2026
CVE-2026-77990 UNKNOWN Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee … Aug 27, 2026
CVE-2026-77989 UNKNOWN Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query … Aug 27, 2026
CVE-2026-77035 UNKNOWN Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with … Aug 27, 2026
CVE-2026-77034 UNKNOWN Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can … Aug 27, 2026
CVE-2026-77018 HIGH 8.8 The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently … Aug 27, 2026
CVE-2026-77017 HIGH 7.7 The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed … Aug 27, 2026
CVE-2026-77016 CRITICAL 9.6 The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or … Aug 27, 2026
CVE-2026-76549 MEDIUM 5.9 The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could … Aug 27, 2026
CVE-2026-59278 MEDIUM 6.5 JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener … Aug 27, 2026
CVE-2026-59275 MEDIUM 6.6 A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located … Aug 27, 2026