Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43798
Total
3549
Critical
13122
High
12955
Medium
CVE ID Severity Score Description Published
CVE-2026-19226 MEDIUM 6.8 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow … Aug 26, 2026
CVE-2026-19220 LOW 3.7 The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated … Aug 26, 2026
CVE-2026-19094 MEDIUM 5.3 The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a … Aug 26, 2026
CVE-2026-16986 MEDIUM 5.3 The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied … Aug 26, 2026
CVE-2026-16984 MEDIUM 6.5 The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on … Aug 26, 2026
CVE-2026-15203 UNKNOWN Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, … Aug 26, 2026
CVE-2026-14550 MEDIUM 5.3 The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available … Aug 26, 2026
CVE-2026-14216 MEDIUM 6.5 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user … Aug 26, 2026
CVE-2026-14212 MEDIUM 4.7 The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, … Aug 26, 2026
CVE-2026-13406 MEDIUM 5.3 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, … Aug 26, 2026
CVE-2026-13404 MEDIUM 5.3 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing … Aug 26, 2026
CVE-2026-13172 MEDIUM 5.3 The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing … Aug 26, 2026
CVE-2026-9805 LOW 2.7 SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. Aug 26, 2026
CVE-2026-9252 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 26, 2026
CVE-2026-9250 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 26, 2026
CVE-2026-9146 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 26, 2026
CVE-2026-80216 UNKNOWN Rejected reason: duplicate record Aug 26, 2026
CVE-2026-80214 UNKNOWN LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server. Aug 26, 2026
CVE-2026-80202 HIGH 8.8 Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with … Aug 26, 2026
CVE-2026-80201 LOW 2.0 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with … Aug 26, 2026
CVE-2026-80200 NONE Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with … Aug 26, 2026
CVE-2026-80199 LOW 3.7 Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response … Aug 26, 2026
CVE-2026-80198 HIGH 7.5 Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers … Aug 26, 2026
CVE-2026-80197 MEDIUM 4.3 Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. … Aug 26, 2026
CVE-2026-80196 HIGH 7.5 Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user … Aug 26, 2026