Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48678
Total
3911
Critical
14443
High
14141
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18146 | HIGH | 7.2 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode … | Aug 13, 2026 |
| CVE-2026-3835 | MEDIUM | 5.3 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in … | Aug 13, 2026 |
| CVE-2026-19088 | MEDIUM | 5.4 | The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log … | Aug 13, 2026 |
| CVE-2026-18945 | HIGH | 8.2 | The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the … | Aug 13, 2026 |
| CVE-2026-14213 | LOW | 3.7 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being … | Aug 13, 2026 |
| CVE-2026-14182 | CRITICAL | 9.8 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an … | Aug 13, 2026 |
| CVE-2026-13610 | UNKNOWN | — | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged … | Aug 13, 2026 |
| CVE-2026-13328 | UNKNOWN | — | The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to … | Aug 13, 2026 |
| CVE-2026-72506 | MEDIUM | 5.4 | VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed … | Aug 13, 2026 |
| CVE-2026-19182 | MEDIUM | 4.3 | An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or … | Aug 13, 2026 |
| CVE-2026-19135 | MEDIUM | 5.4 | A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the … | Aug 13, 2026 |
| CVE-2026-18728 | MEDIUM | 6.5 | A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a … | Aug 13, 2026 |
| CVE-2026-0301 | UNKNOWN | — | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive … | Aug 13, 2026 |
| CVE-2026-0299 | UNKNOWN | — | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and … | Aug 13, 2026 |
| CVE-2026-0298 | UNKNOWN | — | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which … | Aug 13, 2026 |
| CVE-2026-0297 | UNKNOWN | — | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system … | Aug 13, 2026 |
| CVE-2026-0296 | UNKNOWN | — | Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN … | Aug 13, 2026 |
| CVE-2026-0295 | UNKNOWN | — | A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The … | Aug 13, 2026 |
| CVE-2026-0294 | UNKNOWN | — | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute … | Aug 13, 2026 |
| CVE-2026-0293 | UNKNOWN | — | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized … | Aug 13, 2026 |
| CVE-2026-0292 | UNKNOWN | — | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, … | Aug 13, 2026 |
| CVE-2026-0291 | UNKNOWN | — | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low … | Aug 13, 2026 |
| CVE-2026-0290 | UNKNOWN | — | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | Aug 13, 2026 |
| CVE-2026-0289 | UNKNOWN | — | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | Aug 13, 2026 |
| CVE-2026-50544 | MEDIUM | 6.3 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` … | Aug 13, 2026 |