Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19500 | HIGH | 7.5 | The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing … | Aug 18, 2026 |
| CVE-2026-15806 | UNKNOWN | — | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored … | Aug 18, 2026 |
| CVE-2026-12564 | CRITICAL | 9.6 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token … | Aug 18, 2026 |
| CVE-2026-75898 | HIGH | 8.5 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas … | Aug 18, 2026 |
| CVE-2026-75890 | UNKNOWN | — | Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment. | Aug 18, 2026 |
| CVE-2026-75872 | UNKNOWN | — | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary … | Aug 18, 2026 |
| CVE-2026-75784 | CRITICAL | 10.0 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header … | Aug 18, 2026 |
| CVE-2026-75032 | MEDIUM | 6.3 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a … | Aug 18, 2026 |
| CVE-2026-74015 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | Aug 18, 2026 |
| CVE-2026-74012 | HIGH | 8.8 | Editor PHP Object Injection in TaxoPress <= 3.51.0 versions. | Aug 18, 2026 |
| CVE-2026-74009 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | Aug 18, 2026 |
| CVE-2026-74008 | MEDIUM | 5.3 | Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. | Aug 18, 2026 |
| CVE-2026-74007 | MEDIUM | 5.3 | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | Aug 18, 2026 |
| CVE-2026-74006 | MEDIUM | 4.3 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | Aug 18, 2026 |
| CVE-2026-74004 | MEDIUM | 5.4 | Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | Aug 18, 2026 |
| CVE-2026-74003 | MEDIUM | 4.3 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | Aug 18, 2026 |
| CVE-2026-73997 | HIGH | 7.5 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | Aug 18, 2026 |
| CVE-2026-73996 | CRITICAL | 9.8 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | Aug 18, 2026 |
| CVE-2026-73995 | MEDIUM | 5.4 | Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | Aug 18, 2026 |
| CVE-2026-73994 | HIGH | 7.5 | Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | Aug 18, 2026 |
| CVE-2026-73426 | MEDIUM | 4.6 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the … | Aug 18, 2026 |
| CVE-2026-73404 | MEDIUM | 6.5 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | Aug 18, 2026 |
| CVE-2026-73400 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | Aug 18, 2026 |
| CVE-2026-73399 | MEDIUM | 6.5 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | Aug 18, 2026 |
| CVE-2026-73398 | MEDIUM | 6.5 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | Aug 18, 2026 |