Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85094 | HIGH | 8.8 | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with … | Sep 04, 2026 |
| CVE-2026-85085 | CRITICAL | 9.6 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded … | Sep 04, 2026 |
| CVE-2026-84146 | MEDIUM | 5.3 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product … | Sep 04, 2026 |
| CVE-2026-84066 | LOW | 3.1 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified … | Sep 04, 2026 |
| CVE-2026-82194 | MEDIUM | 5.5 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion … | Sep 04, 2026 |
| CVE-2026-82193 | MEDIUM | 5.5 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a … | Sep 04, 2026 |
| CVE-2026-82186 | MEDIUM | 4.1 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with … | Sep 04, 2026 |
| CVE-2026-81347 | MEDIUM | 5.9 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers … | Sep 04, 2026 |
| CVE-2026-81270 | HIGH | 7.5 | Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes … | Sep 04, 2026 |
| CVE-2026-80438 | MEDIUM | 5.9 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as … | Sep 04, 2026 |
| CVE-2026-80181 | UNKNOWN | — | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, … | Sep 04, 2026 |
| CVE-2026-80180 | MEDIUM | 6.1 | Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, … | Sep 04, 2026 |
| CVE-2026-79632 | MEDIUM | 5.3 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification … | Sep 04, 2026 |
| CVE-2026-79631 | MEDIUM | 5.3 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, … | Sep 04, 2026 |
| CVE-2026-79630 | MEDIUM | 5.3 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was … | Sep 04, 2026 |
| CVE-2026-74853 | MEDIUM | 6.8 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above … | Sep 04, 2026 |
| CVE-2026-71216 | UNKNOWN | — | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a … | Sep 04, 2026 |
| CVE-2026-70403 | CRITICAL | 9.8 | XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. | Sep 04, 2026 |
| CVE-2026-69657 | CRITICAL | 9.8 | XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. | Sep 04, 2026 |
| CVE-2026-66840 | HIGH | 7.5 | XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked. | Sep 04, 2026 |
| CVE-2026-62928 | CRITICAL | 9.8 | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. | Sep 04, 2026 |
| CVE-2026-19224 | HIGH | 7.2 | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a … | Sep 04, 2026 |
| CVE-2026-17517 | MEDIUM | 5.3 | The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing … | Sep 04, 2026 |
| CVE-2026-16281 | HIGH | 7.1 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX … | Sep 04, 2026 |
| CVE-2026-15354 | CRITICAL | 9.8 | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization … | Sep 04, 2026 |