Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16601 | HIGH | 8.8 | The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in … | Aug 25, 2026 |
| CVE-2026-78656 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_del.php. The manipulation of the argument … | Aug 25, 2026 |
| CVE-2026-69665 | HIGH | 7.8 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in … | Aug 25, 2026 |
| CVE-2026-68960 | HIGH | 8.5 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in … | Aug 25, 2026 |
| CVE-2026-68959 | HIGH | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a … | Aug 25, 2026 |
| CVE-2026-68062 | HIGH | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a … | Aug 25, 2026 |
| CVE-2026-66109 | HIGH | 7.8 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to … | Aug 25, 2026 |
| CVE-2026-78654 | HIGH | 7.3 | A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads … | Aug 25, 2026 |
| CVE-2026-78638 | LOW | 3.3 | A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component … | Aug 25, 2026 |
| CVE-2026-78478 | HIGH | 8.1 | The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated … | Aug 25, 2026 |
| CVE-2026-78477 | CRITICAL | 9.8 | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers … | Aug 25, 2026 |
| CVE-2026-78470 | MEDIUM | 6.5 | The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping … | Aug 25, 2026 |
| CVE-2026-78467 | MEDIUM | 4.3 | The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up … | Aug 25, 2026 |
| CVE-2026-78466 | MEDIUM | 4.3 | The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing … | Aug 25, 2026 |
| CVE-2025-41741 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 25, 2026 |
| CVE-2026-78637 | HIGH | 7.3 | A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument … | Aug 25, 2026 |
| CVE-2026-13215 | MEDIUM | 6.8 | The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic … | Aug 25, 2026 |
| CVE-2026-13214 | CRITICAL | 9.8 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied … | Aug 25, 2026 |
| CVE-2026-12561 | MEDIUM | 6.4 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This … | Aug 25, 2026 |
| CVE-2026-76063 | MEDIUM | 6.4 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, … | Aug 25, 2026 |
| CVE-2026-75930 | MEDIUM | 4.3 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is … | Aug 25, 2026 |
| CVE-2026-19943 | MEDIUM | 6.4 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all … | Aug 25, 2026 |
| CVE-2026-19892 | HIGH | 8.8 | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due … | Aug 25, 2026 |
| CVE-2026-17089 | MEDIUM | 6.1 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions … | Aug 25, 2026 |
| CVE-2026-14280 | MEDIUM | 6.6 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … | Aug 25, 2026 |