Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73056 | CRITICAL | 9.8 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) … | Aug 16, 2026 |
| CVE-2026-72888 | UNKNOWN | — | Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash … | Aug 16, 2026 |
| CVE-2026-72887 | UNKNOWN | — | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the … | Aug 16, 2026 |
| CVE-2026-19349 | UNKNOWN | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored … | Aug 16, 2026 |
| CVE-2024-58375 | HIGH | 7.5 | OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and … | Aug 16, 2026 |
| CVE-2026-74251 | UNKNOWN | — | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters … | Aug 16, 2026 |
| CVE-2026-74578 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() … | Aug 16, 2026 |
| CVE-2024-13784 | CRITICAL | 9.8 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … | Aug 16, 2026 |
| CVE-2026-2497 | HIGH | 7.2 | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-2357 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-18347 | MEDIUM | 4.3 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17608 | MEDIUM | 6.5 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17604 | MEDIUM | 4.9 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17087 | HIGH | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Aug 16, 2026 |
| CVE-2026-13424 | HIGH | 7.2 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions … | Aug 16, 2026 |
| CVE-2026-12998 | MEDIUM | 5.3 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … | Aug 16, 2026 |
| CVE-2026-10734 | HIGH | 7.2 | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due … | Aug 16, 2026 |
| CVE-2026-9767 | MEDIUM | 6.5 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up … | Aug 16, 2026 |
| CVE-2026-2283 | MEDIUM | 4.9 | The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This … | Aug 16, 2026 |
| CVE-2026-19934 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument … | Aug 16, 2026 |
| CVE-2026-19728 | UNKNOWN | — | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving … | Aug 16, 2026 |
| CVE-2026-19726 | UNKNOWN | — | The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above … | Aug 16, 2026 |
| CVE-2026-19725 | UNKNOWN | — | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to … | Aug 16, 2026 |
| CVE-2026-19717 | UNKNOWN | — | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated … | Aug 16, 2026 |
| CVE-2026-19714 | UNKNOWN | — | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate … | Aug 16, 2026 |