Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82024 | MEDIUM | 5.4 | LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by … | Sep 03, 2026 |
| CVE-2026-82023 | MEDIUM | 4.3 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions … | Sep 03, 2026 |
| CVE-2026-63219 | HIGH | 8.6 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via … | Sep 03, 2026 |
| CVE-2026-58400 | CRITICAL | 9.1 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is … | Sep 03, 2026 |
| CVE-2026-85309 | MEDIUM | 5.3 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from … | Sep 03, 2026 |
| CVE-2026-85308 | MEDIUM | 5.3 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through … | Sep 03, 2026 |
| CVE-2026-85307 | MEDIUM | 5.3 | Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: … | Sep 03, 2026 |
| CVE-2026-85306 | MEDIUM | 6.5 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev … | Sep 03, 2026 |
| CVE-2026-85305 | MEDIUM | 5.4 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. | Sep 03, 2026 |
| CVE-2026-85304 | MEDIUM | 5.3 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects … | Sep 03, 2026 |
| CVE-2026-85303 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking … | Sep 03, 2026 |
| CVE-2026-85302 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects … | Sep 03, 2026 |
| CVE-2026-85242 | UNKNOWN | — | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to … | Sep 03, 2026 |
| CVE-2026-85186 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of … | Sep 03, 2026 |
| CVE-2026-84849 | MEDIUM | 6.5 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | Sep 03, 2026 |
| CVE-2026-84848 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | Sep 03, 2026 |
| CVE-2026-84847 | HIGH | 7.5 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | Sep 03, 2026 |
| CVE-2026-84836 | HIGH | 7.1 | Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | Sep 03, 2026 |
| CVE-2026-84834 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | Sep 03, 2026 |
| CVE-2026-84814 | CRITICAL | 9.8 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | Sep 03, 2026 |
| CVE-2026-84813 | CRITICAL | 9.3 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | Sep 03, 2026 |
| CVE-2026-84812 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | Sep 03, 2026 |
| CVE-2026-84779 | HIGH | 8.1 | Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. | Sep 03, 2026 |
| CVE-2026-84778 | HIGH | 7.5 | Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | Sep 03, 2026 |
| CVE-2026-84777 | HIGH | 7.4 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | Sep 03, 2026 |