Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43590
Total
3522
Critical
13030
High
12889
Medium
CVE ID Severity Score Description Published
CVE-2026-78289 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. Aug 27, 2026
CVE-2026-78288 CRITICAL 9.3 Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. Aug 27, 2026
CVE-2026-78286 CRITICAL 9.8 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. Aug 27, 2026
CVE-2026-78285 HIGH 8.5 Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. Aug 27, 2026
CVE-2026-78283 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. Aug 27, 2026
CVE-2026-78281 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. Aug 27, 2026
CVE-2026-78276 HIGH 7.2 Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. Aug 27, 2026
CVE-2026-78275 MEDIUM 6.8 Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions. Aug 27, 2026
CVE-2026-78274 CRITICAL 9.1 Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. Aug 27, 2026
CVE-2026-78273 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions. Aug 27, 2026
CVE-2026-78271 HIGH 7.2 Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. Aug 27, 2026
CVE-2026-78261 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. Aug 27, 2026
CVE-2026-78260 CRITICAL 9.3 Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. Aug 27, 2026
CVE-2026-78257 HIGH 8.8 Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. Aug 27, 2026
CVE-2026-75020 UNKNOWN Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry … Aug 27, 2026
CVE-2026-75005 UNKNOWN Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count … Aug 27, 2026
CVE-2026-74848 UNKNOWN Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on … Aug 27, 2026
CVE-2026-59355 MEDIUM 6.1 In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request … Aug 27, 2026
CVE-2026-59354 CRITICAL 9.6 In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation … Aug 27, 2026
CVE-2026-32566 CRITICAL 9.8 Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 27, 2026
CVE-2026-32564 HIGH 8.5 Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 27, 2026
CVE-2026-32550 HIGH 8.5 Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. Aug 27, 2026
CVE-2026-32479 CRITICAL 9.3 Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. Aug 27, 2026
CVE-2026-27330 HIGH 8.6 Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. Aug 27, 2026
CVE-2026-78333 HIGH 8.8 The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its … Aug 27, 2026