Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-13214 CRITICAL 9.8 The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied … Aug 25, 2026
CVE-2026-12561 MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This … Aug 25, 2026
CVE-2026-76063 MEDIUM 6.4 The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, … Aug 25, 2026
CVE-2026-75930 MEDIUM 4.3 The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is … Aug 25, 2026
CVE-2026-19943 MEDIUM 6.4 The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all … Aug 25, 2026
CVE-2026-19892 HIGH 8.8 The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due … Aug 25, 2026
CVE-2026-17089 MEDIUM 6.1 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions … Aug 25, 2026
CVE-2026-14280 MEDIUM 6.6 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … Aug 25, 2026
CVE-2026-78685 HIGH 8.8 Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML … Aug 25, 2026
CVE-2026-75982 MEDIUM 4.4 The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX … Aug 25, 2026
CVE-2026-75019 MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored … Aug 25, 2026
CVE-2026-10627 MEDIUM 5.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. … Aug 25, 2026
CVE-2025-9878 MEDIUM 6.4 The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode … Aug 25, 2026
CVE-2026-78683 CRITICAL 9.6 NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, … Aug 25, 2026
CVE-2026-78682 HIGH 7.5 NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested … Aug 25, 2026
CVE-2026-78681 HIGH 7.5 NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with … Aug 25, 2026
CVE-2026-78680 HIGH 7.8 NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary … Aug 25, 2026
CVE-2026-78679 MEDIUM 6.5 GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a … Aug 25, 2026
CVE-2026-78678 MEDIUM 6.5 GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by … Aug 25, 2026
CVE-2026-78677 HIGH 7.5 GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter … Aug 25, 2026
CVE-2026-78676 CRITICAL 9.8 GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft … Aug 25, 2026
CVE-2026-78675 HIGH 8.4 GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. … Aug 25, 2026
CVE-2026-76846 HIGH 7.5 Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit … Aug 25, 2026
CVE-2026-76839 MEDIUM 6.5 Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit … Aug 25, 2026
CVE-2026-75575 MEDIUM 5.3 Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method … Aug 25, 2026