Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45395
Total
3650
Critical
13467
High
13391
Medium
CVE ID Severity Score Description Published
CVE-2026-19500 HIGH 7.5 The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing … Aug 18, 2026
CVE-2026-15806 UNKNOWN The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored … Aug 18, 2026
CVE-2026-12564 CRITICAL 9.6 A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token … Aug 18, 2026
CVE-2026-75898 HIGH 8.5 RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas … Aug 18, 2026
CVE-2026-75890 UNKNOWN Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment. Aug 18, 2026
CVE-2026-75872 UNKNOWN HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary … Aug 18, 2026
CVE-2026-75784 CRITICAL 10.0 A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header … Aug 18, 2026
CVE-2026-75032 MEDIUM 6.3 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a … Aug 18, 2026
CVE-2026-74015 CRITICAL 9.3 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. Aug 18, 2026
CVE-2026-74012 HIGH 8.8 Editor PHP Object Injection in TaxoPress <= 3.51.0 versions. Aug 18, 2026
CVE-2026-74009 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. Aug 18, 2026
CVE-2026-74008 MEDIUM 5.3 Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. Aug 18, 2026
CVE-2026-74007 MEDIUM 5.3 Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. Aug 18, 2026
CVE-2026-74006 MEDIUM 4.3 Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. Aug 18, 2026
CVE-2026-74004 MEDIUM 5.4 Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions. Aug 18, 2026
CVE-2026-74003 MEDIUM 4.3 Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. Aug 18, 2026
CVE-2026-73997 HIGH 7.5 Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. Aug 18, 2026
CVE-2026-73996 CRITICAL 9.8 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. Aug 18, 2026
CVE-2026-73995 MEDIUM 5.4 Subscriber Broken Authentication in User Registration <= 5.2.6 versions. Aug 18, 2026
CVE-2026-73994 HIGH 7.5 Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. Aug 18, 2026
CVE-2026-73426 MEDIUM 4.6 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the … Aug 18, 2026
CVE-2026-73404 MEDIUM 6.5 Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. Aug 18, 2026
CVE-2026-73400 HIGH 8.1 Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. Aug 18, 2026
CVE-2026-73399 MEDIUM 6.5 Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. Aug 18, 2026
CVE-2026-73398 MEDIUM 6.5 Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. Aug 18, 2026