Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14951 | HIGH | 8.0 | An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. | Aug 20, 2026 |
| CVE-2026-14950 | CRITICAL | 9.8 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases … | Aug 20, 2026 |
| CVE-2026-14949 | MEDIUM | 6.5 | A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts … | Aug 20, 2026 |
| CVE-2026-14948 | HIGH | 8.8 | A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for … | Aug 20, 2026 |
| CVE-2026-14947 | HIGH | 7.2 | A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files … | Aug 20, 2026 |
| CVE-2026-14946 | HIGH | 7.2 | A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper … | Aug 20, 2026 |
| CVE-2026-76569 | UNKNOWN | — | Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | Aug 20, 2026 |
| CVE-2026-76565 | UNKNOWN | — | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | Aug 20, 2026 |
| CVE-2026-76564 | UNKNOWN | — | Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 | Aug 20, 2026 |
| CVE-2026-75948 | UNKNOWN | — | Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` … | Aug 20, 2026 |
| CVE-2025-14601 | UNKNOWN | — | An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. … | Aug 20, 2026 |
| CVE-2026-71368 | MEDIUM | 6.1 | F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed. | Aug 20, 2026 |
| CVE-2026-14163 | UNKNOWN | — | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text. | Aug 20, 2026 |
| CVE-2025-14602 | UNKNOWN | — | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess … | Aug 20, 2026 |
| CVE-2026-75963 | HIGH | 7.5 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. … | Aug 20, 2026 |
| CVE-2026-75860 | CRITICAL | 9.8 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every … | Aug 20, 2026 |
| CVE-2026-74992 | MEDIUM | 6.8 | The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not … | Aug 20, 2026 |
| CVE-2026-73542 | LOW | 3.7 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. … | Aug 20, 2026 |
| CVE-2026-19699 | LOW | 2.7 | The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor … | Aug 20, 2026 |
| CVE-2026-19697 | MEDIUM | 6.8 | The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file … | Aug 20, 2026 |
| CVE-2026-19615 | MEDIUM | 6.8 | The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users … | Aug 20, 2026 |
| CVE-2026-17153 | MEDIUM | 5.3 | The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to … | Aug 20, 2026 |
| CVE-2026-15049 | HIGH | 7.2 | The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and … | Aug 20, 2026 |
| CVE-2026-13405 | MEDIUM | 6.6 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later … | Aug 20, 2026 |
| CVE-2026-76957 | MEDIUM | 4.9 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and … | Aug 20, 2026 |