Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44793
Total
3597
Critical
13314
High
13164
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19435 | LOW | 2.7 | The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read … | Aug 21, 2026 |
| CVE-2026-19085 | LOW | 2.7 | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users … | Aug 21, 2026 |
| CVE-2026-18781 | HIGH | 8.1 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file … | Aug 21, 2026 |
| CVE-2026-16962 | MEDIUM | 5.3 | The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, … | Aug 21, 2026 |
| CVE-2026-16959 | MEDIUM | 6.8 | The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its … | Aug 21, 2026 |
| CVE-2026-16577 | LOW | 2.7 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance … | Aug 21, 2026 |
| CVE-2026-16576 | HIGH | 7.2 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API … | Aug 21, 2026 |
| CVE-2026-16575 | MEDIUM | 5.3 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its … | Aug 21, 2026 |
| CVE-2026-14601 | MEDIUM | 6.8 | The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated … | Aug 21, 2026 |
| CVE-2026-14325 | LOW | 3.5 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it … | Aug 21, 2026 |
| CVE-2026-13736 | MEDIUM | 5.3 | The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read … | Aug 21, 2026 |
| CVE-2025-15671 | MEDIUM | 5.4 | The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, … | Aug 21, 2026 |
| CVE-2026-65645 | UNKNOWN | — | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid … | Aug 21, 2026 |
| CVE-2026-65644 | UNKNOWN | — | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, … | Aug 21, 2026 |
| CVE-2026-45202 | UNKNOWN | — | Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused … | Aug 21, 2026 |
| CVE-2026-45201 | UNKNOWN | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading … | Aug 21, 2026 |
| CVE-2026-45199 | UNKNOWN | — | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the … | Aug 21, 2026 |
| CVE-2026-18409 | HIGH | 7.2 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up … | Aug 21, 2026 |
| CVE-2026-76158 | UNKNOWN | — | External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker … | Aug 21, 2026 |
| CVE-2026-76137 | LOW | 3.3 | Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may … | Aug 21, 2026 |
| CVE-2026-76131 | MEDIUM | 5.3 | Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's … | Aug 21, 2026 |
| CVE-2026-73267 | HIGH | 7.7 | A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit … | Aug 21, 2026 |
| CVE-2026-77392 | MEDIUM | 6.3 | A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file … | Aug 21, 2026 |
| CVE-2026-77391 | MEDIUM | 4.3 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation … | Aug 21, 2026 |
| CVE-2026-76157 | UNKNOWN | — | Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker … | Aug 21, 2026 |