Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-85094 HIGH 8.8 The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with … Sep 04, 2026
CVE-2026-85085 CRITICAL 9.6 The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded … Sep 04, 2026
CVE-2026-84146 MEDIUM 5.3 The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product … Sep 04, 2026
CVE-2026-84066 LOW 3.1 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified … Sep 04, 2026
CVE-2026-82194 MEDIUM 5.5 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion … Sep 04, 2026
CVE-2026-82193 MEDIUM 5.5 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a … Sep 04, 2026
CVE-2026-82186 MEDIUM 4.1 The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with … Sep 04, 2026
CVE-2026-81347 MEDIUM 5.9 The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers … Sep 04, 2026
CVE-2026-81270 HIGH 7.5 Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes … Sep 04, 2026
CVE-2026-80438 MEDIUM 5.9 The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as … Sep 04, 2026
CVE-2026-80181 UNKNOWN Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, … Sep 04, 2026
CVE-2026-80180 MEDIUM 6.1 Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, … Sep 04, 2026
CVE-2026-79632 MEDIUM 5.3 The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification … Sep 04, 2026
CVE-2026-79631 MEDIUM 5.3 The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, … Sep 04, 2026
CVE-2026-79630 MEDIUM 5.3 The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was … Sep 04, 2026
CVE-2026-74853 MEDIUM 6.8 The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above … Sep 04, 2026
CVE-2026-71216 UNKNOWN PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a … Sep 04, 2026
CVE-2026-70403 CRITICAL 9.8 XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. Sep 04, 2026
CVE-2026-69657 CRITICAL 9.8 XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. Sep 04, 2026
CVE-2026-66840 HIGH 7.5 XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked. Sep 04, 2026
CVE-2026-62928 CRITICAL 9.8 XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. Sep 04, 2026
CVE-2026-19224 HIGH 7.2 The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a … Sep 04, 2026
CVE-2026-17517 MEDIUM 5.3 The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing … Sep 04, 2026
CVE-2026-16281 HIGH 7.1 The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX … Sep 04, 2026
CVE-2026-15354 CRITICAL 9.8 The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization … Sep 04, 2026