Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46161
Total
3680
Critical
13653
High
13585
Medium
CVE ID Severity Score Description Published
CVE-2026-16950 HIGH 8.6 The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers … Aug 19, 2026
CVE-2026-16617 HIGH 8.8 The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, … Aug 19, 2026
CVE-2026-16616 HIGH 8.6 The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to … Aug 19, 2026
CVE-2026-16570 HIGH 7.1 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin … Aug 19, 2026
CVE-2026-16058 MEDIUM 5.3 The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by … Aug 19, 2026
CVE-2026-15253 MEDIUM 6.8 The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the … Aug 19, 2026
CVE-2026-14861 HIGH 7.5 The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on … Aug 19, 2026
CVE-2026-14826 LOW 2.7 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's … Aug 19, 2026
CVE-2026-14825 LOW 2.7 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing … Aug 19, 2026
CVE-2026-14334 HIGH 8.8 The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that … Aug 19, 2026
CVE-2026-14287 MEDIUM 4.7 The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet … Aug 19, 2026
CVE-2026-14196 MEDIUM 4.3 The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, … Aug 19, 2026
CVE-2026-13175 MEDIUM 6.5 The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and … Aug 19, 2026
CVE-2026-13174 HIGH 7.2 The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently … Aug 19, 2026
CVE-2026-13173 LOW 2.7 The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during … Aug 19, 2026
CVE-2026-13169 HIGH 8.1 The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different … Aug 19, 2026
CVE-2026-12983 HIGH 8.6 The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform … Aug 19, 2026
CVE-2026-11565 HIGH 8.5 The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any … Aug 19, 2026
CVE-2026-70408 HIGH 8.8 An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. Aug 19, 2026
CVE-2026-66358 MEDIUM 6.1 A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. Aug 19, 2026
CVE-2026-49419 UNKNOWN When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the … Aug 19, 2026
CVE-2026-49418 UNKNOWN When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in … Aug 19, 2026
CVE-2026-49415 UNKNOWN During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running … Aug 19, 2026
CVE-2026-19942 HIGH 8.1 The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file … Aug 19, 2026
CVE-2026-76050 HIGH 7.3 A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the … Aug 19, 2026