Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45395
Total
3650
Critical
13467
High
13391
Medium
CVE ID Severity Score Description Published
CVE-2026-66645 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. Aug 18, 2026
CVE-2026-66644 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. Aug 18, 2026
CVE-2026-66643 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. Aug 18, 2026
CVE-2026-66641 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. Aug 18, 2026
CVE-2026-66640 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. Aug 18, 2026
CVE-2026-66639 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. Aug 18, 2026
CVE-2026-66638 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. Aug 18, 2026
CVE-2026-66637 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. Aug 18, 2026
CVE-2026-66636 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. Aug 18, 2026
CVE-2026-66635 HIGH 7.4 Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. Aug 18, 2026
CVE-2026-66634 MEDIUM 4.3 Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. Aug 18, 2026
CVE-2026-66633 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. Aug 18, 2026
CVE-2026-66629 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. Aug 18, 2026
CVE-2026-66627 CRITICAL 9.9 Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. Aug 18, 2026
CVE-2026-66622 HIGH 7.5 Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. Aug 18, 2026
CVE-2026-66621 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. Aug 18, 2026
CVE-2026-66620 HIGH 7.2 Editor PHP Object Injection in OptionTree <= 2.7.3 versions. Aug 18, 2026
CVE-2026-66046 HIGH 7.5 Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes … Aug 18, 2026
CVE-2026-63639 HIGH 8.8 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns … Aug 18, 2026
CVE-2026-63632 LOW 3.3 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() … Aug 18, 2026
CVE-2026-61407 HIGH 8.8 Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could … Aug 18, 2026
CVE-2026-59949 MEDIUM 6.5 yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and … Aug 18, 2026
CVE-2026-59940 CRITICAL 9.8 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values … Aug 18, 2026
CVE-2026-59825 HIGH 7.4 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP … Aug 18, 2026
CVE-2026-56684 HIGH 7.5 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger … Aug 18, 2026