Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42028
Total
3422
Critical
12413
High
12340
Medium
CVE ID Severity Score Description Published
CVE-2026-2688 MEDIUM 6.5 The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for … Sep 02, 2026
CVE-2026-19698 LOW 3.5 The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it … Sep 02, 2026
CVE-2026-17563 MEDIUM 5.3 The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated … Sep 02, 2026
CVE-2026-14326 LOW 3.8 The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role … Sep 02, 2026
CVE-2026-14255 MEDIUM 5.5 A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to … Sep 02, 2026
CVE-2026-10821 MEDIUM 6.6 The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file … Sep 02, 2026
CVE-2025-9314 CRITICAL 9.8 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component Sep 02, 2026
CVE-2025-8945 MEDIUM 5.3 The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. Sep 02, 2026
CVE-2025-15692 LOW 3.5 The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow … Sep 02, 2026
CVE-2025-15490 MEDIUM 5.3 The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs Sep 02, 2026
CVE-2025-15489 MEDIUM 5.3 The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected … Sep 02, 2026
CVE-2025-15485 HIGH 8.2 The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them … Sep 02, 2026
CVE-2025-15481 MEDIUM 5.3 The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. Sep 02, 2026
CVE-2025-13398 UNKNOWN Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability … Sep 02, 2026
CVE-2024-7956 UNKNOWN A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor … Sep 02, 2026
CVE-2024-3773 MEDIUM 5.9 The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where … Sep 02, 2026
CVE-2023-3360 LOW 3.3 The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a … Sep 02, 2026
CVE-2026-81269 MEDIUM 5.3 Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. Sep 02, 2026
CVE-2026-81205 MEDIUM 5.3 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue … Sep 02, 2026
CVE-2026-81201 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from … Sep 02, 2026
CVE-2026-81168 LOW 3.7 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from … Sep 02, 2026
CVE-2026-81167 MEDIUM 4.8 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: … Sep 02, 2026
CVE-2026-81166 MEDIUM 5.3 Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. Sep 02, 2026
CVE-2026-81165 MEDIUM 5.3 Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. Sep 02, 2026
CVE-2026-81164 MEDIUM 5.4 Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. Sep 02, 2026