Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81772 | HIGH | 8.8 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | Sep 02, 2026 |
| CVE-2026-81771 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | Sep 02, 2026 |
| CVE-2026-81770 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | Sep 02, 2026 |
| CVE-2026-81769 | HIGH | 8.8 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | Sep 02, 2026 |
| CVE-2026-81294 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | Sep 02, 2026 |
| CVE-2026-81289 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | Sep 02, 2026 |
| CVE-2026-81288 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | Sep 02, 2026 |
| CVE-2026-81286 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | Sep 02, 2026 |
| CVE-2026-81283 | HIGH | 8.8 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | Sep 02, 2026 |
| CVE-2026-66652 | MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1. | Sep 02, 2026 |
| CVE-2026-82958 | UNKNOWN | — | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved … | Sep 02, 2026 |
| CVE-2026-32773 | MEDIUM | 6.1 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped … | Sep 02, 2026 |
| CVE-2026-19219 | HIGH | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an … | Sep 02, 2026 |
| CVE-2026-18672 | HIGH | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is … | Sep 02, 2026 |
| CVE-2026-84175 | UNKNOWN | — | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in … | Sep 02, 2026 |
| CVE-2026-53683 | MEDIUM | 4.3 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' … | Sep 02, 2026 |
| CVE-2026-75528 | HIGH | 7.2 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, … | Sep 02, 2026 |
| CVE-2026-23591 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23590 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23589 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23588 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23587 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23586 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23585 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-23584 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |