Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48124
Total
3850
Critical
14244
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-59505 HIGH 8.6 CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59504 CRITICAL 9.1 CWE-602: Client-Side Enforcement of Server-Side Security Aug 13, 2026
CVE-2026-59503 CRITICAL 9.1 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor Aug 13, 2026
CVE-2026-59502 MEDIUM 5.3 CWE-203: Observable Discrepancy Aug 13, 2026
CVE-2026-59501 HIGH 8.2 CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59500 CRITICAL 10.0 CWE-287: Improper Authentication Aug 13, 2026
CVE-2026-59499 HIGH 8.6 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Aug 13, 2026
CVE-2026-19484 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart … Aug 13, 2026
CVE-2026-11970 UNKNOWN This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. Aug 13, 2026
CVE-2026-19696 MEDIUM 6.6 Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows Aug 13, 2026
CVE-2026-19695 MEDIUM 4.7 Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service Aug 13, 2026
CVE-2026-19694 MEDIUM 4.7 TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service Aug 13, 2026
CVE-2026-19481 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a … Aug 13, 2026
CVE-2026-16459 UNKNOWN Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to … Aug 13, 2026
CVE-2026-16458 UNKNOWN Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts … Aug 13, 2026
CVE-2026-15413 CRITICAL 10.0 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by … Aug 13, 2026
CVE-2026-14332 MEDIUM 5.4 The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management … Aug 13, 2026
CVE-2026-14298 MEDIUM 6.5 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, … Aug 13, 2026
CVE-2026-3639 MEDIUM 6.4 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up … Aug 13, 2026
CVE-2026-11840 HIGH 8.8 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. Aug 13, 2026
CVE-2026-18622 MEDIUM 4.7 Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into … Aug 13, 2026
CVE-2026-18146 HIGH 7.2 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode … Aug 13, 2026
CVE-2026-3835 MEDIUM 5.3 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in … Aug 13, 2026
CVE-2026-19088 MEDIUM 5.4 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log … Aug 13, 2026
CVE-2026-18945 HIGH 8.2 The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the … Aug 13, 2026