Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26091
Total
1954
Critical
7964
High
8211
Medium
CVE ID Severity Score Description Published
CVE-2026-12079 MEDIUM 6.5 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due … Jun 25, 2026
CVE-2026-12077 HIGH 7.5 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and … Jun 25, 2026
CVE-2026-10833 MEDIUM 6.4 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block … Jun 25, 2026
CVE-2026-8662 LOW 3.3 Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted … Jun 25, 2026
CVE-2026-8658 MEDIUM 6.0 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters … Jun 25, 2026
CVE-2026-8666 HIGH 7.7 OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … Jun 25, 2026
CVE-2026-8665 HIGH 7.7 OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … Jun 25, 2026
CVE-2026-8664 MEDIUM 6.0 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters … Jun 25, 2026
CVE-2026-8660 HIGH 7.7 OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … Jun 25, 2026
CVE-2026-8592 HIGH 7.7 OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the … Jun 25, 2026
CVE-2026-9155 HIGH 8.8 OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to … Jun 25, 2026
CVE-2026-9154 HIGH 7.1 Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression … Jun 25, 2026
CVE-2026-9153 MEDIUM 6.5 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient … Jun 25, 2026
CVE-2026-57589 HIGH 7.4 sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget(). Jun 25, 2026
CVE-2026-9787 HIGH 8.8 Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9786 HIGH 8.8 Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9785 HIGH 8.8 Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9784 HIGH 8.8 Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9783 HIGH 8.8 Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9782 HIGH 8.8 Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9781 HIGH 8.8 Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026
CVE-2026-9780 HIGH 8.8 Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User … Jun 25, 2026
CVE-2026-8663 MEDIUM 6.0 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name … Jun 25, 2026
CVE-2026-8659 MEDIUM 6.0 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters … Jun 25, 2026
CVE-2026-7570 HIGH 8.8 Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault … Jun 25, 2026