Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27197
Total
2065
Critical
8240
High
8439
Medium
CVE ID Severity Score Description Published
CVE-2026-7566 MEDIUM 6.6 The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via … Jun 06, 2026
CVE-2026-7565 MEDIUM 4.9 The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and … Jun 06, 2026
CVE-2026-7537 HIGH 7.2 The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. … Jun 06, 2026
CVE-2026-2500 MEDIUM 4.4 The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` … Jun 06, 2026
CVE-2026-9281 MEDIUM 6.4 The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Jun 06, 2026
CVE-2026-9008 MEDIUM 4.3 The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function … Jun 06, 2026
CVE-2026-8901 HIGH 7.2 The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form … Jun 06, 2026
CVE-2026-8438 HIGH 7.2 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This … Jun 06, 2026
CVE-2026-9719 MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … Jun 06, 2026
CVE-2026-9290 HIGH 7.5 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … Jun 06, 2026
CVE-2026-8976 MEDIUM 4.3 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in … Jun 06, 2026
CVE-2026-8900 MEDIUM 6.4 The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due … Jun 06, 2026
CVE-2026-8893 MEDIUM 6.4 The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up … Jun 06, 2026
CVE-2026-8608 MEDIUM 5.3 The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and … Jun 06, 2026
CVE-2026-7047 MEDIUM 4.3 The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to … Jun 06, 2026
CVE-2026-6448 MEDIUM 4.9 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' … Jun 06, 2026
CVE-2026-6242 UNKNOWN An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting … Jun 06, 2026
CVE-2026-6241 UNKNOWN An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without … Jun 06, 2026
CVE-2026-6240 UNKNOWN A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion … Jun 06, 2026
CVE-2026-6239 UNKNOWN A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device fails to properly validate the number of … Jun 06, 2026
CVE-2026-34123 UNKNOWN On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a logic … Jun 06, 2026
CVE-2026-10038 MEDIUM 4.3 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / … Jun 06, 2026
CVE-2025-12656 LOW 3.8 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in … Jun 06, 2026
CVE-2026-7654 HIGH 8.8 The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This … Jun 05, 2026
CVE-2026-7523 MEDIUM 4.3 The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin … Jun 05, 2026