Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-72695 HIGH 8.1 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames … Aug 25, 2026
CVE-2026-56710 CRITICAL 9.8 Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can … Aug 25, 2026
CVE-2026-56709 HIGH 7.5 Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to … Aug 25, 2026
CVE-2026-56708 MEDIUM 5.3 Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers … Aug 25, 2026
CVE-2026-56707 HIGH 7.7 Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render … Aug 25, 2026
CVE-2026-56706 MEDIUM 6.8 Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), … Aug 25, 2026
CVE-2026-56705 CRITICAL 9.8 Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers … Aug 25, 2026
CVE-2026-56704 MEDIUM 6.1 Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server … Aug 25, 2026
CVE-2026-56703 HIGH 7.2 Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can … Aug 25, 2026
CVE-2026-56702 HIGH 8.8 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a … Aug 25, 2026
CVE-2026-34968 HIGH 8.1 Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An … Aug 25, 2026
CVE-2026-34967 MEDIUM 5.4 Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user … Aug 25, 2026
CVE-2026-34964 MEDIUM 5.8 Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and … Aug 25, 2026
CVE-2026-34959 MEDIUM 4.7 Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can … Aug 25, 2026
CVE-2026-19801 MEDIUM 4.3 The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up … Aug 25, 2026
CVE-2026-16434 UNKNOWN Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching … Aug 25, 2026
CVE-2026-15023 MEDIUM 6.5 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action … Aug 25, 2026
CVE-2026-10630 MEDIUM 4.3 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in … Aug 25, 2026
CVE-2026-66766 HIGH 7.5 SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted … Aug 25, 2026
CVE-2026-59183 MEDIUM 5.5 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 … Aug 25, 2026
CVE-2026-55373 MEDIUM 6.2 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and … Aug 25, 2026
CVE-2026-55371 UNKNOWN OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 … Aug 25, 2026
CVE-2026-55059 MEDIUM 6.1 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and … Aug 25, 2026
CVE-2026-54920 NONE OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … Aug 25, 2026
CVE-2026-53532 UNKNOWN OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a … Aug 24, 2026