Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47587
Total
3849
Critical
14223
High
13906
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16094 | MEDIUM | 4.9 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in … | Aug 15, 2026 |
| CVE-2026-15993 | MEDIUM | 5.3 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder … | Aug 15, 2026 |
| CVE-2026-15948 | MEDIUM | 6.4 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions … | Aug 15, 2026 |
| CVE-2026-15453 | MEDIUM | 6.5 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions … | Aug 15, 2026 |
| CVE-2026-13360 | HIGH | 7.2 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in … | Aug 15, 2026 |
| CVE-2026-8840 | MEDIUM | 5.3 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due … | Aug 15, 2026 |
| CVE-2026-16080 | MEDIUM | 6.5 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, … | Aug 15, 2026 |
| CVE-2026-15965 | HIGH | 8.8 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up … | Aug 15, 2026 |
| CVE-2026-15341 | CRITICAL | 9.8 | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The … | Aug 15, 2026 |
| CVE-2026-15312 | HIGH | 8.8 | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due … | Aug 15, 2026 |
| CVE-2026-15303 | CRITICAL | 9.8 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX … | Aug 15, 2026 |
| CVE-2026-15162 | HIGH | 7.5 | The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback … | Aug 15, 2026 |
| CVE-2026-15001 | HIGH | 8.8 | The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is … | Aug 15, 2026 |
| CVE-2026-14484 | CRITICAL | 9.1 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path … | Aug 15, 2026 |
| CVE-2026-14433 | HIGH | 7.2 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all … | Aug 15, 2026 |
| CVE-2026-12128 | MEDIUM | 5.3 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and … | Aug 15, 2026 |
| CVE-2026-74250 | MEDIUM | 6.3 | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. | Aug 14, 2026 |
| CVE-2026-74247 | MEDIUM | 4.2 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability … | Aug 14, 2026 |
| CVE-2026-74245 | MEDIUM | 5.9 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without … | Aug 14, 2026 |
| CVE-2026-74244 | MEDIUM | 5.9 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted … | Aug 14, 2026 |
| CVE-2026-74243 | MEDIUM | 6.5 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to … | Aug 14, 2026 |
| CVE-2026-74242 | MEDIUM | 5.3 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can … | Aug 14, 2026 |
| CVE-2026-74241 | MEDIUM | 4.8 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the … | Aug 14, 2026 |
| CVE-2026-74240 | MEDIUM | 5.4 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related … | Aug 14, 2026 |
| CVE-2026-63650 | UNKNOWN | — | OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field | Aug 14, 2026 |