Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
27197
Total
2065
Critical
8240
High
8439
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7566 | MEDIUM | 6.6 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via … | Jun 06, 2026 |
| CVE-2026-7565 | MEDIUM | 4.9 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and … | Jun 06, 2026 |
| CVE-2026-7537 | HIGH | 7.2 | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. … | Jun 06, 2026 |
| CVE-2026-2500 | MEDIUM | 4.4 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` … | Jun 06, 2026 |
| CVE-2026-9281 | MEDIUM | 6.4 | The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Jun 06, 2026 |
| CVE-2026-9008 | MEDIUM | 4.3 | The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function … | Jun 06, 2026 |
| CVE-2026-8901 | HIGH | 7.2 | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form … | Jun 06, 2026 |
| CVE-2026-8438 | HIGH | 7.2 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This … | Jun 06, 2026 |
| CVE-2026-9719 | MEDIUM | 4.3 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | Jun 06, 2026 |
| CVE-2026-9290 | HIGH | 7.5 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … | Jun 06, 2026 |
| CVE-2026-8976 | MEDIUM | 4.3 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in … | Jun 06, 2026 |
| CVE-2026-8900 | MEDIUM | 6.4 | The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due … | Jun 06, 2026 |
| CVE-2026-8893 | MEDIUM | 6.4 | The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up … | Jun 06, 2026 |
| CVE-2026-8608 | MEDIUM | 5.3 | The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and … | Jun 06, 2026 |
| CVE-2026-7047 | MEDIUM | 4.3 | The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to … | Jun 06, 2026 |
| CVE-2026-6448 | MEDIUM | 4.9 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' … | Jun 06, 2026 |
| CVE-2026-6242 | UNKNOWN | — | An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting … | Jun 06, 2026 |
| CVE-2026-6241 | UNKNOWN | — | An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without … | Jun 06, 2026 |
| CVE-2026-6240 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion … | Jun 06, 2026 |
| CVE-2026-6239 | UNKNOWN | — | A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device fails to properly validate the number of … | Jun 06, 2026 |
| CVE-2026-34123 | UNKNOWN | — | On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a logic … | Jun 06, 2026 |
| CVE-2026-10038 | MEDIUM | 4.3 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / … | Jun 06, 2026 |
| CVE-2025-12656 | LOW | 3.8 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in … | Jun 06, 2026 |
| CVE-2026-7654 | HIGH | 8.8 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This … | Jun 05, 2026 |
| CVE-2026-7523 | MEDIUM | 4.3 | The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin … | Jun 05, 2026 |