Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43798
Total
3549
Critical
13122
High
12955
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15366 | UNKNOWN | — | A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page | Aug 26, 2026 |
| CVE-2026-15365 | UNKNOWN | — | A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app. | Aug 26, 2026 |
| CVE-2026-79654 | MEDIUM | 4.3 | A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the … | Aug 26, 2026 |
| CVE-2026-78146 | MEDIUM | 6.5 | The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that … | Aug 26, 2026 |
| CVE-2026-77790 | UNKNOWN | — | The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege … | Aug 26, 2026 |
| CVE-2026-77789 | MEDIUM | 4.3 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the … | Aug 26, 2026 |
| CVE-2026-77758 | MEDIUM | 5.3 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation … | Aug 26, 2026 |
| CVE-2026-77757 | MEDIUM | 5.4 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the … | Aug 26, 2026 |
| CVE-2026-77754 | MEDIUM | 5.3 | The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users … | Aug 26, 2026 |
| CVE-2026-77695 | MEDIUM | 6.5 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX … | Aug 26, 2026 |
| CVE-2026-77694 | MEDIUM | 5.3 | The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated … | Aug 26, 2026 |
| CVE-2026-77693 | HIGH | 8.7 | The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict … | Aug 26, 2026 |
| CVE-2026-75798 | MEDIUM | 5.3 | The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it … | Aug 26, 2026 |
| CVE-2026-75797 | HIGH | 7.7 | The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file … | Aug 26, 2026 |
| CVE-2026-74930 | MEDIUM | 4.3 | The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in … | Aug 26, 2026 |
| CVE-2026-74929 | MEDIUM | 5.4 | The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any … | Aug 26, 2026 |
| CVE-2026-74928 | HIGH | 7.5 | The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with … | Aug 26, 2026 |
| CVE-2026-74851 | HIGH | 7.2 | The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role … | Aug 26, 2026 |
| CVE-2026-58097 | HIGH | 7.8 | mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to … | Aug 26, 2026 |
| CVE-2026-58096 | CRITICAL | 9.8 | LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. … | Aug 26, 2026 |
| CVE-2026-58095 | CRITICAL | 9.8 | mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious … | Aug 26, 2026 |
| CVE-2026-58094 | HIGH | 7.8 | The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, … | Aug 26, 2026 |
| CVE-2026-58093 | HIGH | 7.0 | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not … | Aug 26, 2026 |
| CVE-2026-19760 | HIGH | 7.2 | The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up … | Aug 26, 2026 |
| CVE-2026-19718 | HIGH | 8.1 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before … | Aug 26, 2026 |