Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47587
Total
3849
Critical
14223
High
13906
Medium
CVE ID Severity Score Description Published
CVE-2026-16094 MEDIUM 4.9 The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in … Aug 15, 2026
CVE-2026-15993 MEDIUM 5.3 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder … Aug 15, 2026
CVE-2026-15948 MEDIUM 6.4 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions … Aug 15, 2026
CVE-2026-15453 MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions … Aug 15, 2026
CVE-2026-13360 HIGH 7.2 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in … Aug 15, 2026
CVE-2026-8840 MEDIUM 5.3 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due … Aug 15, 2026
CVE-2026-16080 MEDIUM 6.5 The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, … Aug 15, 2026
CVE-2026-15965 HIGH 8.8 The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up … Aug 15, 2026
CVE-2026-15341 CRITICAL 9.8 The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The … Aug 15, 2026
CVE-2026-15312 HIGH 8.8 The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due … Aug 15, 2026
CVE-2026-15303 CRITICAL 9.8 The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX … Aug 15, 2026
CVE-2026-15162 HIGH 7.5 The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback … Aug 15, 2026
CVE-2026-15001 HIGH 8.8 The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is … Aug 15, 2026
CVE-2026-14484 CRITICAL 9.1 The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path … Aug 15, 2026
CVE-2026-14433 HIGH 7.2 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all … Aug 15, 2026
CVE-2026-12128 MEDIUM 5.3 The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and … Aug 15, 2026
CVE-2026-74250 MEDIUM 6.3 In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. Aug 14, 2026
CVE-2026-74247 MEDIUM 4.2 A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability … Aug 14, 2026
CVE-2026-74245 MEDIUM 5.9 A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without … Aug 14, 2026
CVE-2026-74244 MEDIUM 5.9 A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted … Aug 14, 2026
CVE-2026-74243 MEDIUM 6.5 A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to … Aug 14, 2026
CVE-2026-74242 MEDIUM 5.3 A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can … Aug 14, 2026
CVE-2026-74241 MEDIUM 4.8 A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the … Aug 14, 2026
CVE-2026-74240 MEDIUM 5.4 A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related … Aug 14, 2026
CVE-2026-63650 UNKNOWN OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field Aug 14, 2026