Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74783 | HIGH | 7.5 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates … | Aug 16, 2026 |
| CVE-2026-73062 | HIGH | 7.5 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic … | Aug 16, 2026 |
| CVE-2026-73061 | CRITICAL | 9.8 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify … | Aug 16, 2026 |
| CVE-2026-73060 | HIGH | 7.5 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a … | Aug 16, 2026 |
| CVE-2026-73059 | MEDIUM | 6.5 | stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access … | Aug 16, 2026 |
| CVE-2026-73058 | MEDIUM | 5.8 | stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy … | Aug 16, 2026 |
| CVE-2026-73057 | HIGH | 7.5 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can … | Aug 16, 2026 |
| CVE-2026-73056 | CRITICAL | 9.8 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) … | Aug 16, 2026 |
| CVE-2026-72888 | UNKNOWN | — | Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash … | Aug 16, 2026 |
| CVE-2026-72887 | UNKNOWN | — | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the … | Aug 16, 2026 |
| CVE-2026-19349 | UNKNOWN | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored … | Aug 16, 2026 |
| CVE-2024-58375 | HIGH | 7.5 | OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and … | Aug 16, 2026 |
| CVE-2026-74251 | UNKNOWN | — | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters … | Aug 16, 2026 |
| CVE-2026-74578 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() … | Aug 16, 2026 |
| CVE-2024-13784 | CRITICAL | 9.8 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … | Aug 16, 2026 |
| CVE-2026-2497 | HIGH | 7.2 | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-2357 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-18347 | MEDIUM | 4.3 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17608 | MEDIUM | 6.5 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17604 | MEDIUM | 4.9 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-17087 | HIGH | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Aug 16, 2026 |
| CVE-2026-13424 | HIGH | 7.2 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions … | Aug 16, 2026 |
| CVE-2026-12998 | MEDIUM | 5.3 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … | Aug 16, 2026 |
| CVE-2026-10734 | HIGH | 7.2 | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due … | Aug 16, 2026 |
| CVE-2026-9767 | MEDIUM | 6.5 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up … | Aug 16, 2026 |