Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26091
Total
1954
Critical
7964
High
8211
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12079 | MEDIUM | 6.5 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due … | Jun 25, 2026 |
| CVE-2026-12077 | HIGH | 7.5 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and … | Jun 25, 2026 |
| CVE-2026-10833 | MEDIUM | 6.4 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block … | Jun 25, 2026 |
| CVE-2026-8662 | LOW | 3.3 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted … | Jun 25, 2026 |
| CVE-2026-8658 | MEDIUM | 6.0 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters … | Jun 25, 2026 |
| CVE-2026-8666 | HIGH | 7.7 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … | Jun 25, 2026 |
| CVE-2026-8665 | HIGH | 7.7 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … | Jun 25, 2026 |
| CVE-2026-8664 | MEDIUM | 6.0 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters … | Jun 25, 2026 |
| CVE-2026-8660 | HIGH | 7.7 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … | Jun 25, 2026 |
| CVE-2026-8592 | HIGH | 7.7 | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … | Jun 25, 2026 |
| CVE-2026-9155 | HIGH | 8.8 | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to … | Jun 25, 2026 |
| CVE-2026-9154 | HIGH | 7.1 | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression … | Jun 25, 2026 |
| CVE-2026-9153 | MEDIUM | 6.5 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient … | Jun 25, 2026 |
| CVE-2026-57589 | HIGH | 7.4 | sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget(). | Jun 25, 2026 |
| CVE-2026-9787 | HIGH | 8.8 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9786 | HIGH | 8.8 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9785 | HIGH | 8.8 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9784 | HIGH | 8.8 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9783 | HIGH | 8.8 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9782 | HIGH | 8.8 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9781 | HIGH | 8.8 | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |
| CVE-2026-9780 | HIGH | 8.8 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User … | Jun 25, 2026 |
| CVE-2026-8663 | MEDIUM | 6.0 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name … | Jun 25, 2026 |
| CVE-2026-8659 | MEDIUM | 6.0 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters … | Jun 25, 2026 |
| CVE-2026-7570 | HIGH | 8.8 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … | Jun 25, 2026 |