Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28475
Total
2191
Critical
8537
High
8862
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8040 | MEDIUM | 6.4 | The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up … | May 27, 2026 |
| CVE-2026-7614 | MEDIUM | 4.3 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to … | May 27, 2026 |
| CVE-2026-6268 | HIGH | 7.1 | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the … | May 27, 2026 |
| CVE-2026-9236 | MEDIUM | 4.3 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | May 27, 2026 |
| CVE-2026-8450 | CRITICAL | 9.1 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets … | May 27, 2026 |
| CVE-2026-6287 | MEDIUM | 5.4 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple … | May 27, 2026 |
| CVE-2026-49000 | HIGH | 7.0 | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to … | May 27, 2026 |
| CVE-2025-14481 | MEDIUM | 4.3 | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to … | May 27, 2026 |
| CVE-2026-9022 | MEDIUM | 6.4 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 … | May 27, 2026 |
| CVE-2026-48999 | MEDIUM | 5.7 | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts … | May 27, 2026 |
| CVE-2026-48962 | HIGH | 7.3 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in … | May 27, 2026 |
| CVE-2026-48961 | UNKNOWN | — | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte … | May 27, 2026 |
| CVE-2026-48959 | UNKNOWN | — | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, … | May 27, 2026 |
| CVE-2026-2255 | MEDIUM | 4.3 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the … | May 27, 2026 |
| CVE-2026-2254 | MEDIUM | 6.3 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related … | May 27, 2026 |
| CVE-2026-2253 | HIGH | 7.7 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external … | May 27, 2026 |
| CVE-2025-15649 | UNKNOWN | — | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and … | May 27, 2026 |
| CVE-2026-9632 | HIGH | 8.8 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of … | May 27, 2026 |
| CVE-2026-9631 | HIGH | 8.8 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the … | May 27, 2026 |
| CVE-2026-9628 | HIGH | 8.8 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web … | May 27, 2026 |
| CVE-2026-9627 | HIGH | 8.8 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component … | May 27, 2026 |
| CVE-2026-9609 | MEDIUM | 4.7 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password … | May 27, 2026 |
| CVE-2026-9608 | LOW | 2.4 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator … | May 27, 2026 |
| CVE-2026-9207 | HIGH | 8.8 | Tanium addressed an unauthorized code execution vulnerability in Connect. | May 27, 2026 |
| CVE-2026-9156 | MEDIUM | 6.5 | Tanium addressed a denial of service vulnerability in Tanium Server. | May 27, 2026 |