Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-78435 LOW 3.8 A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. … Aug 24, 2026
CVE-2026-78434 MEDIUM 6.5 A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. … Aug 24, 2026
CVE-2026-78284 HIGH 8.6 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. Aug 24, 2026
CVE-2026-78282 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. Aug 24, 2026
CVE-2026-78268 HIGH 7.5 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. Aug 24, 2026
CVE-2026-78267 CRITICAL 9.8 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. Aug 24, 2026
CVE-2026-78266 MEDIUM 6.5 Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. Aug 24, 2026
CVE-2026-78265 CRITICAL 9.8 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. Aug 24, 2026
CVE-2026-78264 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. Aug 24, 2026
CVE-2026-78263 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. Aug 24, 2026
CVE-2026-78262 CRITICAL 9.8 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. Aug 24, 2026
CVE-2026-78259 HIGH 7.3 Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. Aug 24, 2026
CVE-2026-77384 HIGH 7.5 libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but … Aug 24, 2026
CVE-2026-77337 UNKNOWN CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and … Aug 24, 2026
CVE-2026-68516 MEDIUM 6.5 OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a … Aug 24, 2026
CVE-2026-45404 UNKNOWN OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a … Aug 24, 2026
CVE-2026-32563 CRITICAL 9.8 Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. Aug 24, 2026
CVE-2026-32561 HIGH 8.8 Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. Aug 24, 2026
CVE-2026-32560 HIGH 8.8 Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. Aug 24, 2026
CVE-2026-32559 CRITICAL 9.9 Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. Aug 24, 2026
CVE-2026-32556 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. Aug 24, 2026
CVE-2026-32555 CRITICAL 9.3 Unauthenticated SQL Injection in Boost <= 2.0.4 versions. Aug 24, 2026
CVE-2026-32554 CRITICAL 9.3 Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. Aug 24, 2026
CVE-2026-27364 MEDIUM 6.5 Subscriber Broken Access Control in Style Kits <= 2.6.5 versions. Aug 24, 2026
CVE-2026-17113 MEDIUM 6.0 A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI … Aug 24, 2026