Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77945 | HIGH | 7.4 | A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of … | Aug 22, 2026 |
| CVE-2026-78003 | CRITICAL | 9.8 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This … | Aug 22, 2026 |
| CVE-2026-12710 | UNKNOWN | — | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal … | Aug 22, 2026 |
| CVE-2026-77002 | UNKNOWN | — | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users … | Aug 22, 2026 |
| CVE-2026-77001 | UNKNOWN | — | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one … | Aug 22, 2026 |
| CVE-2026-77000 | UNKNOWN | — | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating … | Aug 22, 2026 |
| CVE-2026-76793 | UNKNOWN | — | The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a … | Aug 22, 2026 |
| CVE-2026-76789 | UNKNOWN | — | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and … | Aug 22, 2026 |
| CVE-2026-19222 | UNKNOWN | — | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to … | Aug 22, 2026 |
| CVE-2026-19221 | UNKNOWN | — | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a … | Aug 22, 2026 |
| CVE-2026-19093 | UNKNOWN | — | The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor … | Aug 22, 2026 |
| CVE-2026-18052 | UNKNOWN | — | The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an … | Aug 22, 2026 |
| CVE-2026-16738 | UNKNOWN | — | The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to … | Aug 22, 2026 |
| CVE-2026-16612 | UNKNOWN | — | The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected … | Aug 22, 2026 |
| CVE-2026-16260 | UNKNOWN | — | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting … | Aug 22, 2026 |
| CVE-2026-14187 | UNKNOWN | — | The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role … | Aug 22, 2026 |
| CVE-2026-76074 | MEDIUM | 4.3 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions … | Aug 22, 2026 |
| CVE-2026-76057 | MEDIUM | 4.3 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions … | Aug 22, 2026 |
| CVE-2026-75027 | MEDIUM | 5.3 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin … | Aug 22, 2026 |
| CVE-2026-19883 | HIGH | 8.8 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing … | Aug 22, 2026 |
| CVE-2026-77781 | UNKNOWN | — | Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on … | Aug 22, 2026 |
| CVE-2026-9052 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-76069 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-73323 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-53541 | MEDIUM | 4.3 | OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly … | Aug 21, 2026 |