Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-82024 MEDIUM 5.4 LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by … Sep 03, 2026
CVE-2026-82023 MEDIUM 4.3 LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions … Sep 03, 2026
CVE-2026-63219 HIGH 8.6 GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via … Sep 03, 2026
CVE-2026-58400 CRITICAL 9.1 GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is … Sep 03, 2026
CVE-2026-85309 MEDIUM 5.3 Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from … Sep 03, 2026
CVE-2026-85308 MEDIUM 5.3 Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through … Sep 03, 2026
CVE-2026-85307 MEDIUM 5.3 Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: … Sep 03, 2026
CVE-2026-85306 MEDIUM 6.5 Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev … Sep 03, 2026
CVE-2026-85305 MEDIUM 5.4 Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. Sep 03, 2026
CVE-2026-85304 MEDIUM 5.3 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects … Sep 03, 2026
CVE-2026-85303 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking … Sep 03, 2026
CVE-2026-85302 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects … Sep 03, 2026
CVE-2026-85242 UNKNOWN PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to … Sep 03, 2026
CVE-2026-85186 MEDIUM 6.3 A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of … Sep 03, 2026
CVE-2026-84849 MEDIUM 6.5 Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. Sep 03, 2026
CVE-2026-84848 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. Sep 03, 2026
CVE-2026-84847 HIGH 7.5 Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. Sep 03, 2026
CVE-2026-84836 HIGH 7.1 Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. Sep 03, 2026
CVE-2026-84834 CRITICAL 9.8 Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. Sep 03, 2026
CVE-2026-84814 CRITICAL 9.8 Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. Sep 03, 2026
CVE-2026-84813 CRITICAL 9.3 Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. Sep 03, 2026
CVE-2026-84812 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. Sep 03, 2026
CVE-2026-84779 HIGH 8.1 Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions. Sep 03, 2026
CVE-2026-84778 HIGH 7.5 Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions. Sep 03, 2026
CVE-2026-84777 HIGH 7.4 Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. Sep 03, 2026