Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78289 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | Aug 27, 2026 |
| CVE-2026-78288 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | Aug 27, 2026 |
| CVE-2026-78286 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | Aug 27, 2026 |
| CVE-2026-78285 | HIGH | 8.5 | Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | Aug 27, 2026 |
| CVE-2026-78283 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | Aug 27, 2026 |
| CVE-2026-78281 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | Aug 27, 2026 |
| CVE-2026-78276 | HIGH | 7.2 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | Aug 27, 2026 |
| CVE-2026-78275 | MEDIUM | 6.8 | Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions. | Aug 27, 2026 |
| CVE-2026-78274 | CRITICAL | 9.1 | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | Aug 27, 2026 |
| CVE-2026-78273 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions. | Aug 27, 2026 |
| CVE-2026-78271 | HIGH | 7.2 | Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | Aug 27, 2026 |
| CVE-2026-78261 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | Aug 27, 2026 |
| CVE-2026-78260 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | Aug 27, 2026 |
| CVE-2026-78257 | HIGH | 8.8 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | Aug 27, 2026 |
| CVE-2026-75020 | UNKNOWN | — | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry … | Aug 27, 2026 |
| CVE-2026-75005 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count … | Aug 27, 2026 |
| CVE-2026-74848 | UNKNOWN | — | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on … | Aug 27, 2026 |
| CVE-2026-59355 | MEDIUM | 6.1 | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request … | Aug 27, 2026 |
| CVE-2026-59354 | CRITICAL | 9.6 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation … | Aug 27, 2026 |
| CVE-2026-32566 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | Aug 27, 2026 |
| CVE-2026-32564 | HIGH | 8.5 | Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | Aug 27, 2026 |
| CVE-2026-32550 | HIGH | 8.5 | Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | Aug 27, 2026 |
| CVE-2026-32479 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | Aug 27, 2026 |
| CVE-2026-27330 | HIGH | 8.6 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | Aug 27, 2026 |
| CVE-2026-78333 | HIGH | 8.8 | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its … | Aug 27, 2026 |