Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44750
Total
3597
Critical
13289
High
13145
Medium
CVE ID Severity Score Description Published
CVE-2026-77945 HIGH 7.4 A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of … Aug 22, 2026
CVE-2026-78003 CRITICAL 9.8 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This … Aug 22, 2026
CVE-2026-12710 UNKNOWN A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal … Aug 22, 2026
CVE-2026-77002 UNKNOWN The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users … Aug 22, 2026
CVE-2026-77001 UNKNOWN The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one … Aug 22, 2026
CVE-2026-77000 UNKNOWN The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating … Aug 22, 2026
CVE-2026-76793 UNKNOWN The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a … Aug 22, 2026
CVE-2026-76789 UNKNOWN The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and … Aug 22, 2026
CVE-2026-19222 UNKNOWN The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to … Aug 22, 2026
CVE-2026-19221 UNKNOWN The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a … Aug 22, 2026
CVE-2026-19093 UNKNOWN The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor … Aug 22, 2026
CVE-2026-18052 UNKNOWN The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an … Aug 22, 2026
CVE-2026-16738 UNKNOWN The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to … Aug 22, 2026
CVE-2026-16612 UNKNOWN The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected … Aug 22, 2026
CVE-2026-16260 UNKNOWN The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting … Aug 22, 2026
CVE-2026-14187 UNKNOWN The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role … Aug 22, 2026
CVE-2026-76074 MEDIUM 4.3 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions … Aug 22, 2026
CVE-2026-76057 MEDIUM 4.3 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions … Aug 22, 2026
CVE-2026-75027 MEDIUM 5.3 The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin … Aug 22, 2026
CVE-2026-19883 HIGH 8.8 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing … Aug 22, 2026
CVE-2026-77781 UNKNOWN Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on … Aug 22, 2026
CVE-2026-9052 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 21, 2026
CVE-2026-76069 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 21, 2026
CVE-2026-73323 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 21, 2026
CVE-2026-53541 MEDIUM 4.3 OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly … Aug 21, 2026