Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-78572 HIGH 8.1 The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. … Aug 25, 2026
CVE-2026-78570 CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated … Aug 25, 2026
CVE-2026-76128 MEDIUM 6.4 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 … Aug 25, 2026
CVE-2026-75038 MEDIUM 6.1 UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0. Aug 25, 2026
CVE-2026-75037 HIGH 7.0 Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit … Aug 25, 2026
CVE-2026-49050 HIGH 8.8 General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which … Aug 25, 2026
CVE-2026-16231 HIGH 8.1 hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during … Aug 25, 2026
CVE-2026-12878 UNKNOWN In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. Aug 25, 2026
CVE-2026-78568 CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the … Aug 25, 2026
CVE-2026-78566 HIGH 8.1 The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated … Aug 25, 2026
CVE-2026-78563 HIGH 7.2 The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization … Aug 25, 2026
CVE-2026-78562 HIGH 8.1 The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for … Aug 25, 2026
CVE-2026-77146 UNKNOWN The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to … Aug 25, 2026
CVE-2026-77145 UNKNOWN The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with … Aug 25, 2026
CVE-2026-77144 UNKNOWN The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. … Aug 25, 2026
CVE-2026-77143 UNKNOWN The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a … Aug 25, 2026
CVE-2026-77142 UNKNOWN The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, … Aug 25, 2026
CVE-2026-77141 UNKNOWN The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check … Aug 25, 2026
CVE-2026-77140 UNKNOWN The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that … Aug 25, 2026
CVE-2026-77139 UNKNOWN The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An … Aug 25, 2026
CVE-2026-77138 UNKNOWN The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted … Aug 25, 2026
CVE-2026-77137 UNKNOWN The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary … Aug 25, 2026
CVE-2026-77136 UNKNOWN The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View … Aug 25, 2026
CVE-2026-77135 UNKNOWN The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to … Aug 25, 2026
CVE-2026-77134 UNKNOWN The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor … Aug 25, 2026