Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66645 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | Aug 18, 2026 |
| CVE-2026-66644 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | Aug 18, 2026 |
| CVE-2026-66643 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | Aug 18, 2026 |
| CVE-2026-66641 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | Aug 18, 2026 |
| CVE-2026-66640 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | Aug 18, 2026 |
| CVE-2026-66639 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | Aug 18, 2026 |
| CVE-2026-66638 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | Aug 18, 2026 |
| CVE-2026-66637 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | Aug 18, 2026 |
| CVE-2026-66636 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | Aug 18, 2026 |
| CVE-2026-66635 | HIGH | 7.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | Aug 18, 2026 |
| CVE-2026-66634 | MEDIUM | 4.3 | Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. | Aug 18, 2026 |
| CVE-2026-66633 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | Aug 18, 2026 |
| CVE-2026-66629 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | Aug 18, 2026 |
| CVE-2026-66627 | CRITICAL | 9.9 | Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | Aug 18, 2026 |
| CVE-2026-66622 | HIGH | 7.5 | Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | Aug 18, 2026 |
| CVE-2026-66621 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. | Aug 18, 2026 |
| CVE-2026-66620 | HIGH | 7.2 | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | Aug 18, 2026 |
| CVE-2026-66046 | HIGH | 7.5 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes … | Aug 18, 2026 |
| CVE-2026-63639 | HIGH | 8.8 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns … | Aug 18, 2026 |
| CVE-2026-63632 | LOW | 3.3 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() … | Aug 18, 2026 |
| CVE-2026-61407 | HIGH | 8.8 | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could … | Aug 18, 2026 |
| CVE-2026-59949 | MEDIUM | 6.5 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and … | Aug 18, 2026 |
| CVE-2026-59940 | CRITICAL | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values … | Aug 18, 2026 |
| CVE-2026-59825 | HIGH | 7.4 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP … | Aug 18, 2026 |
| CVE-2026-56684 | HIGH | 7.5 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger … | Aug 18, 2026 |