Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47944
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-14456 HIGH 7.5 Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue … Aug 13, 2026
CVE-2026-14256 MEDIUM 4.7 ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a … Aug 13, 2026
CVE-2026-12036 HIGH 7.1 An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to … Aug 13, 2026
CVE-2026-73403 MEDIUM 5.3 Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. Aug 13, 2026
CVE-2026-73401 MEDIUM 5.3 Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. Aug 13, 2026
CVE-2026-73357 MEDIUM 6.5 Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. Aug 13, 2026
CVE-2026-73353 MEDIUM 5.3 Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. Aug 13, 2026
CVE-2026-73349 MEDIUM 5.3 Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. Aug 13, 2026
CVE-2026-73346 HIGH 7.6 Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. Aug 13, 2026
CVE-2026-73344 MEDIUM 5.9 Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. Aug 13, 2026
CVE-2026-73340 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. Aug 13, 2026
CVE-2026-73188 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. Aug 13, 2026
CVE-2026-67991 HIGH 7.5 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name … Aug 13, 2026
CVE-2026-67990 MEDIUM 5.4 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to … Aug 13, 2026
CVE-2026-67986 HIGH 8.4 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a … Aug 13, 2026
CVE-2026-66704 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. Aug 13, 2026
CVE-2026-66700 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. Aug 13, 2026
CVE-2026-66698 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. Aug 13, 2026
CVE-2026-66697 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. Aug 13, 2026
CVE-2026-66693 MEDIUM 6.5 Subscriber Broken Access Control in Motors <= 1.4.113 versions. Aug 13, 2026
CVE-2026-66691 CRITICAL 9.8 Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. Aug 13, 2026
CVE-2026-66689 MEDIUM 6.3 Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions. Aug 13, 2026
CVE-2026-66687 MEDIUM 6.5 Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. Aug 13, 2026
CVE-2026-66661 HIGH 7.7 Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. Aug 13, 2026
CVE-2026-66660 MEDIUM 6.5 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. Aug 13, 2026