Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48678
Total
3911
Critical
14443
High
14141
Medium
CVE ID Severity Score Description Published
CVE-2026-18146 HIGH 7.2 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode … Aug 13, 2026
CVE-2026-3835 MEDIUM 5.3 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in … Aug 13, 2026
CVE-2026-19088 MEDIUM 5.4 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log … Aug 13, 2026
CVE-2026-18945 HIGH 8.2 The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the … Aug 13, 2026
CVE-2026-14213 LOW 3.7 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being … Aug 13, 2026
CVE-2026-14182 CRITICAL 9.8 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an … Aug 13, 2026
CVE-2026-13610 UNKNOWN The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged … Aug 13, 2026
CVE-2026-13328 UNKNOWN The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to … Aug 13, 2026
CVE-2026-72506 MEDIUM 5.4 VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed … Aug 13, 2026
CVE-2026-19182 MEDIUM 4.3 An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or … Aug 13, 2026
CVE-2026-19135 MEDIUM 5.4 A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the … Aug 13, 2026
CVE-2026-18728 MEDIUM 6.5 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a … Aug 13, 2026
CVE-2026-0301 UNKNOWN An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive … Aug 13, 2026
CVE-2026-0299 UNKNOWN Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and … Aug 13, 2026
CVE-2026-0298 UNKNOWN An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which … Aug 13, 2026
CVE-2026-0297 UNKNOWN A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system … Aug 13, 2026
CVE-2026-0296 UNKNOWN Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN … Aug 13, 2026
CVE-2026-0295 UNKNOWN A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The … Aug 13, 2026
CVE-2026-0294 UNKNOWN A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute … Aug 13, 2026
CVE-2026-0293 UNKNOWN A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized … Aug 13, 2026
CVE-2026-0292 UNKNOWN An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, … Aug 13, 2026
CVE-2026-0291 UNKNOWN An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low … Aug 13, 2026
CVE-2026-0290 UNKNOWN An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. Aug 13, 2026
CVE-2026-0289 UNKNOWN A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. Aug 13, 2026
CVE-2026-50544 MEDIUM 6.3 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` … Aug 13, 2026