Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49322 | MEDIUM | 4.3 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read … | May 29, 2026 |
| CVE-2026-3655 | CRITICAL | 9.8 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to … | May 29, 2026 |
| CVE-2025-11262 | HIGH | 7.2 | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 … | May 29, 2026 |
| CVE-2026-9714 | MEDIUM | 6.4 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, … | May 29, 2026 |
| CVE-2026-9493 | MEDIUM | 6.5 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific … | May 29, 2026 |
| CVE-2026-8732 | CRITICAL | 9.8 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This … | May 29, 2026 |
| CVE-2026-6324 | MEDIUM | 4.8 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious … | May 29, 2026 |
| CVE-2026-6275 | MEDIUM | 6.4 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This … | May 29, 2026 |
| CVE-2025-14042 | MEDIUM | 6.4 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in … | May 29, 2026 |
| CVE-2025-11993 | HIGH | 8.8 | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via … | May 29, 2026 |
| CVE-2026-2128 | MEDIUM | 5.3 | The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This … | May 29, 2026 |
| CVE-2026-8995 | MEDIUM | 4.3 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including … | May 29, 2026 |
| CVE-2026-7430 | MEDIUM | 4.4 | The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient … | May 29, 2026 |
| CVE-2026-8070 | UNKNOWN | — | Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and … | May 29, 2026 |
| CVE-2026-7480 | UNKNOWN | — | An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary … | May 29, 2026 |
| CVE-2026-6892 | MEDIUM | 5.0 | Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a … | May 29, 2026 |
| CVE-2026-6891 | MEDIUM | 5.0 | Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login … | May 29, 2026 |
| CVE-2026-9999 | HIGH | 8.8 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a … | May 28, 2026 |
| CVE-2026-9998 | HIGH | 8.3 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … | May 28, 2026 |
| CVE-2026-9997 | HIGH | 8.3 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a … | May 28, 2026 |
| CVE-2026-9996 | MEDIUM | 6.5 | Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process … | May 28, 2026 |
| CVE-2026-9995 | HIGH | 8.8 | Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | May 28, 2026 |
| CVE-2026-9994 | HIGH | 8.3 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially … | May 28, 2026 |
| CVE-2026-9993 | HIGH | 8.3 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a … | May 28, 2026 |
| CVE-2026-9992 | HIGH | 8.8 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | May 28, 2026 |