Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45002
Total
3609
Critical
13358
High
13243
Medium
CVE ID Severity Score Description Published
CVE-2026-14334 HIGH 8.8 The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that … Aug 19, 2026
CVE-2026-14287 MEDIUM 4.7 The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet … Aug 19, 2026
CVE-2026-14196 MEDIUM 4.3 The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, … Aug 19, 2026
CVE-2026-13175 MEDIUM 6.5 The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and … Aug 19, 2026
CVE-2026-13174 HIGH 7.2 The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently … Aug 19, 2026
CVE-2026-13173 LOW 2.7 The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during … Aug 19, 2026
CVE-2026-13169 HIGH 8.1 The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different … Aug 19, 2026
CVE-2026-12983 HIGH 8.6 The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform … Aug 19, 2026
CVE-2026-11565 HIGH 8.5 The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any … Aug 19, 2026
CVE-2026-70408 HIGH 8.8 An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. Aug 19, 2026
CVE-2026-66358 MEDIUM 6.1 A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. Aug 19, 2026
CVE-2026-49419 UNKNOWN When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the … Aug 19, 2026
CVE-2026-49418 UNKNOWN When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in … Aug 19, 2026
CVE-2026-49415 UNKNOWN During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running … Aug 19, 2026
CVE-2026-19942 HIGH 8.1 The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file … Aug 19, 2026
CVE-2026-76050 HIGH 7.3 A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the … Aug 19, 2026
CVE-2026-76049 HIGH 7.3 A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of … Aug 19, 2026
CVE-2026-76048 HIGH 7.3 A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing … Aug 19, 2026
CVE-2026-76014 LOW 3.3 A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such … Aug 19, 2026
CVE-2026-76008 CRITICAL 10.0 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This … Aug 19, 2026
CVE-2026-76004 CRITICAL 9.9 A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp … Aug 19, 2026
CVE-2026-76003 CRITICAL 9.9 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of … Aug 19, 2026
CVE-2026-75987 HIGH 7.3 A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. … Aug 19, 2026
CVE-2026-75986 HIGH 7.3 A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the … Aug 19, 2026
CVE-2026-75985 HIGH 7.4 A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of the argument … Aug 19, 2026