Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14334 | HIGH | 8.8 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that … | Aug 19, 2026 |
| CVE-2026-14287 | MEDIUM | 4.7 | The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet … | Aug 19, 2026 |
| CVE-2026-14196 | MEDIUM | 4.3 | The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, … | Aug 19, 2026 |
| CVE-2026-13175 | MEDIUM | 6.5 | The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and … | Aug 19, 2026 |
| CVE-2026-13174 | HIGH | 7.2 | The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently … | Aug 19, 2026 |
| CVE-2026-13173 | LOW | 2.7 | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during … | Aug 19, 2026 |
| CVE-2026-13169 | HIGH | 8.1 | The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different … | Aug 19, 2026 |
| CVE-2026-12983 | HIGH | 8.6 | The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform … | Aug 19, 2026 |
| CVE-2026-11565 | HIGH | 8.5 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any … | Aug 19, 2026 |
| CVE-2026-70408 | HIGH | 8.8 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | Aug 19, 2026 |
| CVE-2026-66358 | MEDIUM | 6.1 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | Aug 19, 2026 |
| CVE-2026-49419 | UNKNOWN | — | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the … | Aug 19, 2026 |
| CVE-2026-49418 | UNKNOWN | — | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in … | Aug 19, 2026 |
| CVE-2026-49415 | UNKNOWN | — | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running … | Aug 19, 2026 |
| CVE-2026-19942 | HIGH | 8.1 | The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file … | Aug 19, 2026 |
| CVE-2026-76050 | HIGH | 7.3 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the … | Aug 19, 2026 |
| CVE-2026-76049 | HIGH | 7.3 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of … | Aug 19, 2026 |
| CVE-2026-76048 | HIGH | 7.3 | A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing … | Aug 19, 2026 |
| CVE-2026-76014 | LOW | 3.3 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such … | Aug 19, 2026 |
| CVE-2026-76008 | CRITICAL | 10.0 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This … | Aug 19, 2026 |
| CVE-2026-76004 | CRITICAL | 9.9 | A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp … | Aug 19, 2026 |
| CVE-2026-76003 | CRITICAL | 9.9 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of … | Aug 19, 2026 |
| CVE-2026-75987 | HIGH | 7.3 | A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. … | Aug 19, 2026 |
| CVE-2026-75986 | HIGH | 7.3 | A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the … | Aug 19, 2026 |
| CVE-2026-75985 | HIGH | 7.4 | A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of the argument … | Aug 19, 2026 |