Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-2688 | MEDIUM | 6.5 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for … | Sep 02, 2026 |
| CVE-2026-19698 | LOW | 3.5 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it … | Sep 02, 2026 |
| CVE-2026-17563 | MEDIUM | 5.3 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated … | Sep 02, 2026 |
| CVE-2026-14326 | LOW | 3.8 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role … | Sep 02, 2026 |
| CVE-2026-14255 | MEDIUM | 5.5 | A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to … | Sep 02, 2026 |
| CVE-2026-10821 | MEDIUM | 6.6 | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file … | Sep 02, 2026 |
| CVE-2025-9314 | CRITICAL | 9.8 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | Sep 02, 2026 |
| CVE-2025-8945 | MEDIUM | 5.3 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | Sep 02, 2026 |
| CVE-2025-15692 | LOW | 3.5 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow … | Sep 02, 2026 |
| CVE-2025-15490 | MEDIUM | 5.3 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs | Sep 02, 2026 |
| CVE-2025-15489 | MEDIUM | 5.3 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected … | Sep 02, 2026 |
| CVE-2025-15485 | HIGH | 8.2 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them … | Sep 02, 2026 |
| CVE-2025-15481 | MEDIUM | 5.3 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | Sep 02, 2026 |
| CVE-2025-13398 | UNKNOWN | — | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability … | Sep 02, 2026 |
| CVE-2024-7956 | UNKNOWN | — | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor … | Sep 02, 2026 |
| CVE-2024-3773 | MEDIUM | 5.9 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where … | Sep 02, 2026 |
| CVE-2023-3360 | LOW | 3.3 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a … | Sep 02, 2026 |
| CVE-2026-81269 | MEDIUM | 5.3 | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | Sep 02, 2026 |
| CVE-2026-81205 | MEDIUM | 5.3 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue … | Sep 02, 2026 |
| CVE-2026-81201 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from … | Sep 02, 2026 |
| CVE-2026-81168 | LOW | 3.7 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from … | Sep 02, 2026 |
| CVE-2026-81167 | MEDIUM | 4.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: … | Sep 02, 2026 |
| CVE-2026-81166 | MEDIUM | 5.3 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | Sep 02, 2026 |
| CVE-2026-81165 | MEDIUM | 5.3 | Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. | Sep 02, 2026 |
| CVE-2026-81164 | MEDIUM | 5.4 | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | Sep 02, 2026 |