Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-23583 | UNKNOWN | — | Rejected reason: Withdrawn by requester. | Sep 02, 2026 |
| CVE-2026-14828 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL … | Sep 02, 2026 |
| CVE-2025-7963 | MEDIUM | 6.4 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 … | Sep 02, 2026 |
| CVE-2026-82883 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: … | Sep 02, 2026 |
| CVE-2026-3850 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and … | Sep 02, 2026 |
| CVE-2026-82183 | HIGH | 8.1 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers … | Sep 02, 2026 |
| CVE-2026-82182 | MEDIUM | 4.1 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a … | Sep 02, 2026 |
| CVE-2026-81807 | HIGH | 8.8 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes … | Sep 02, 2026 |
| CVE-2026-81737 | HIGH | 8.8 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in … | Sep 02, 2026 |
| CVE-2026-81583 | MEDIUM | 5.4 | The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a … | Sep 02, 2026 |
| CVE-2026-81432 | MEDIUM | 4.3 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in … | Sep 02, 2026 |
| CVE-2026-81428 | MEDIUM | 6.5 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users … | Sep 02, 2026 |
| CVE-2026-81427 | MEDIUM | 4.3 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing … | Sep 02, 2026 |
| CVE-2026-81426 | MEDIUM | 4.3 | The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers … | Sep 02, 2026 |
| CVE-2026-81199 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to … | Sep 02, 2026 |
| CVE-2026-81198 | LOW | 3.8 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users … | Sep 02, 2026 |
| CVE-2026-81197 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it … | Sep 02, 2026 |
| CVE-2026-81196 | LOW | 2.7 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read … | Sep 02, 2026 |
| CVE-2026-81195 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated … | Sep 02, 2026 |
| CVE-2026-81194 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers … | Sep 02, 2026 |
| CVE-2026-80467 | HIGH | 8.1 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form … | Sep 02, 2026 |
| CVE-2026-79621 | MEDIUM | 4.3 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry … | Sep 02, 2026 |
| CVE-2026-78657 | CRITICAL | 9.8 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files … | Sep 02, 2026 |
| CVE-2026-78151 | MEDIUM | 5.3 | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public … | Sep 02, 2026 |
| CVE-2026-77792 | HIGH | 7.5 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, … | Sep 02, 2026 |