Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43798
Total
3549
Critical
13122
High
12955
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19226 | MEDIUM | 6.8 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow … | Aug 26, 2026 |
| CVE-2026-19220 | LOW | 3.7 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated … | Aug 26, 2026 |
| CVE-2026-19094 | MEDIUM | 5.3 | The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a … | Aug 26, 2026 |
| CVE-2026-16986 | MEDIUM | 5.3 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied … | Aug 26, 2026 |
| CVE-2026-16984 | MEDIUM | 6.5 | The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on … | Aug 26, 2026 |
| CVE-2026-15203 | UNKNOWN | — | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, … | Aug 26, 2026 |
| CVE-2026-14550 | MEDIUM | 5.3 | The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available … | Aug 26, 2026 |
| CVE-2026-14216 | MEDIUM | 6.5 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user … | Aug 26, 2026 |
| CVE-2026-14212 | MEDIUM | 4.7 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, … | Aug 26, 2026 |
| CVE-2026-13406 | MEDIUM | 5.3 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, … | Aug 26, 2026 |
| CVE-2026-13404 | MEDIUM | 5.3 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing … | Aug 26, 2026 |
| CVE-2026-13172 | MEDIUM | 5.3 | The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing … | Aug 26, 2026 |
| CVE-2026-9805 | LOW | 2.7 | SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. | Aug 26, 2026 |
| CVE-2026-9252 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2026-9250 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2026-9146 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2026-80216 | UNKNOWN | — | Rejected reason: duplicate record | Aug 26, 2026 |
| CVE-2026-80214 | UNKNOWN | — | LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server. | Aug 26, 2026 |
| CVE-2026-80202 | HIGH | 8.8 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with … | Aug 26, 2026 |
| CVE-2026-80201 | LOW | 2.0 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with … | Aug 26, 2026 |
| CVE-2026-80200 | NONE | — | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with … | Aug 26, 2026 |
| CVE-2026-80199 | LOW | 3.7 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response … | Aug 26, 2026 |
| CVE-2026-80198 | HIGH | 7.5 | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers … | Aug 26, 2026 |
| CVE-2026-80197 | MEDIUM | 4.3 | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. … | Aug 26, 2026 |
| CVE-2026-80196 | HIGH | 7.5 | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user … | Aug 26, 2026 |