Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48124
Total
3850
Critical
14244
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59505 | HIGH | 8.6 | CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59504 | CRITICAL | 9.1 | CWE-602: Client-Side Enforcement of Server-Side Security | Aug 13, 2026 |
| CVE-2026-59503 | CRITICAL | 9.1 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor | Aug 13, 2026 |
| CVE-2026-59502 | MEDIUM | 5.3 | CWE-203: Observable Discrepancy | Aug 13, 2026 |
| CVE-2026-59501 | HIGH | 8.2 | CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59500 | CRITICAL | 10.0 | CWE-287: Improper Authentication | Aug 13, 2026 |
| CVE-2026-59499 | HIGH | 8.6 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | Aug 13, 2026 |
| CVE-2026-19484 | HIGH | 7.5 | @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart … | Aug 13, 2026 |
| CVE-2026-11970 | UNKNOWN | — | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. | Aug 13, 2026 |
| CVE-2026-19696 | MEDIUM | 6.6 | Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows | Aug 13, 2026 |
| CVE-2026-19695 | MEDIUM | 4.7 | Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service | Aug 13, 2026 |
| CVE-2026-19694 | MEDIUM | 4.7 | TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service | Aug 13, 2026 |
| CVE-2026-19481 | HIGH | 7.5 | @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a … | Aug 13, 2026 |
| CVE-2026-16459 | UNKNOWN | — | Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to … | Aug 13, 2026 |
| CVE-2026-16458 | UNKNOWN | — | Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts … | Aug 13, 2026 |
| CVE-2026-15413 | CRITICAL | 10.0 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by … | Aug 13, 2026 |
| CVE-2026-14332 | MEDIUM | 5.4 | The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management … | Aug 13, 2026 |
| CVE-2026-14298 | MEDIUM | 6.5 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, … | Aug 13, 2026 |
| CVE-2026-3639 | MEDIUM | 6.4 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up … | Aug 13, 2026 |
| CVE-2026-11840 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | Aug 13, 2026 |
| CVE-2026-18622 | MEDIUM | 4.7 | Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into … | Aug 13, 2026 |
| CVE-2026-18146 | HIGH | 7.2 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode … | Aug 13, 2026 |
| CVE-2026-3835 | MEDIUM | 5.3 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in … | Aug 13, 2026 |
| CVE-2026-19088 | MEDIUM | 5.4 | The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log … | Aug 13, 2026 |
| CVE-2026-18945 | HIGH | 8.2 | The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the … | Aug 13, 2026 |