Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10630 | MEDIUM | 4.3 | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in … | Aug 25, 2026 |
| CVE-2026-66766 | HIGH | 7.5 | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted … | Aug 25, 2026 |
| CVE-2026-59183 | MEDIUM | 5.5 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 … | Aug 25, 2026 |
| CVE-2026-55373 | MEDIUM | 6.2 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and … | Aug 25, 2026 |
| CVE-2026-55371 | UNKNOWN | — | OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 … | Aug 25, 2026 |
| CVE-2026-55059 | MEDIUM | 6.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and … | Aug 25, 2026 |
| CVE-2026-54920 | NONE | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … | Aug 25, 2026 |
| CVE-2026-53532 | UNKNOWN | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … | Aug 24, 2026 |
| CVE-2026-78435 | LOW | 3.8 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. … | Aug 24, 2026 |
| CVE-2026-78434 | MEDIUM | 6.5 | A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. … | Aug 24, 2026 |
| CVE-2026-78284 | HIGH | 8.6 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | Aug 24, 2026 |
| CVE-2026-78282 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | Aug 24, 2026 |
| CVE-2026-78268 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | Aug 24, 2026 |
| CVE-2026-78267 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | Aug 24, 2026 |
| CVE-2026-78266 | MEDIUM | 6.5 | Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. | Aug 24, 2026 |
| CVE-2026-78265 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | Aug 24, 2026 |
| CVE-2026-78264 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | Aug 24, 2026 |
| CVE-2026-78263 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | Aug 24, 2026 |
| CVE-2026-78262 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | Aug 24, 2026 |
| CVE-2026-78259 | HIGH | 7.3 | Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | Aug 24, 2026 |
| CVE-2026-77384 | HIGH | 7.5 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but … | Aug 24, 2026 |
| CVE-2026-77337 | UNKNOWN | — | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and … | Aug 24, 2026 |
| CVE-2026-68516 | MEDIUM | 6.5 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a … | Aug 24, 2026 |
| CVE-2026-45404 | UNKNOWN | — | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a … | Aug 24, 2026 |
| CVE-2026-32563 | CRITICAL | 9.8 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | Aug 24, 2026 |