Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-84776 HIGH 7.5 Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. Sep 03, 2026
CVE-2026-84774 MEDIUM 6.1 Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. Sep 03, 2026
CVE-2026-84773 HIGH 7.2 Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. Sep 03, 2026
CVE-2026-84769 MEDIUM 6.5 Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. Sep 03, 2026
CVE-2026-84768 CRITICAL 9.3 Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. Sep 03, 2026
CVE-2026-84767 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. Sep 03, 2026
CVE-2026-84766 MEDIUM 5.9 Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. Sep 03, 2026
CVE-2026-84765 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. Sep 03, 2026
CVE-2026-84763 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions. Sep 03, 2026
CVE-2026-84762 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. Sep 03, 2026
CVE-2026-84761 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. Sep 03, 2026
CVE-2026-84758 MEDIUM 6.5 Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. Sep 03, 2026
CVE-2026-84757 HIGH 8.2 Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. Sep 03, 2026
CVE-2026-84756 HIGH 7.1 Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. Sep 03, 2026
CVE-2026-84755 MEDIUM 6.5 Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. Sep 03, 2026
CVE-2026-84754 MEDIUM 6.5 Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. Sep 03, 2026
CVE-2026-84753 CRITICAL 9.8 Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. Sep 03, 2026
CVE-2026-84752 HIGH 8.8 Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. Sep 03, 2026
CVE-2026-84736 UNKNOWN In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for … Sep 03, 2026
CVE-2026-84238 CRITICAL 9.8 Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. Sep 03, 2026
CVE-2026-84215 MEDIUM 6.5 Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. Sep 03, 2026
CVE-2026-81776 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. Sep 03, 2026
CVE-2026-81773 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. Sep 03, 2026
CVE-2026-81300 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. Sep 03, 2026
CVE-2026-81295 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. Sep 03, 2026