Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-10630 MEDIUM 4.3 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in … Aug 25, 2026
CVE-2026-66766 HIGH 7.5 SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted … Aug 25, 2026
CVE-2026-59183 MEDIUM 5.5 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 … Aug 25, 2026
CVE-2026-55373 MEDIUM 6.2 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and … Aug 25, 2026
CVE-2026-55371 UNKNOWN OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 … Aug 25, 2026
CVE-2026-55059 MEDIUM 6.1 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and … Aug 25, 2026
CVE-2026-54920 NONE OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … Aug 25, 2026
CVE-2026-53532 UNKNOWN OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … Aug 24, 2026
CVE-2026-78435 LOW 3.8 A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. … Aug 24, 2026
CVE-2026-78434 MEDIUM 6.5 A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. … Aug 24, 2026
CVE-2026-78284 HIGH 8.6 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. Aug 24, 2026
CVE-2026-78282 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. Aug 24, 2026
CVE-2026-78268 HIGH 7.5 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. Aug 24, 2026
CVE-2026-78267 CRITICAL 9.8 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. Aug 24, 2026
CVE-2026-78266 MEDIUM 6.5 Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. Aug 24, 2026
CVE-2026-78265 CRITICAL 9.8 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. Aug 24, 2026
CVE-2026-78264 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. Aug 24, 2026
CVE-2026-78263 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. Aug 24, 2026
CVE-2026-78262 CRITICAL 9.8 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. Aug 24, 2026
CVE-2026-78259 HIGH 7.3 Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. Aug 24, 2026
CVE-2026-77384 HIGH 7.5 libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but … Aug 24, 2026
CVE-2026-77337 UNKNOWN CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and … Aug 24, 2026
CVE-2026-68516 MEDIUM 6.5 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a … Aug 24, 2026
CVE-2026-45404 UNKNOWN OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a … Aug 24, 2026
CVE-2026-32563 CRITICAL 9.8 Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 24, 2026