Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28490
Total
2193
Critical
8546
High
8865
Medium
CVE ID Severity Score Description Published
CVE-2026-24592 MEDIUM 5.3 Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a … May 25, 2026
CVE-2026-24586 MEDIUM 5.4 Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77. May 25, 2026
CVE-2026-24582 MEDIUM 4.3 Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0. May 25, 2026
CVE-2026-24554 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1. May 25, 2026
CVE-2026-24527 MEDIUM 4.3 Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects … May 25, 2026
CVE-2025-62745 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a … May 25, 2026
CVE-2026-9503 LOW 3.3 A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG … May 25, 2026
CVE-2026-9502 MEDIUM 5.3 A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The … May 25, 2026
CVE-2026-9501 LOW 3.3 A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread … May 25, 2026
CVE-2026-9500 MEDIUM 5.3 A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread … May 25, 2026
CVE-2026-48852 LOW 3.7 PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. May 25, 2026
CVE-2026-48851 LOW 3.1 PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared … May 25, 2026
CVE-2026-48850 LOW 3.7 PuTTY 0.72 before 0.84 has a double free in RSA KEX. May 25, 2026
CVE-2026-48589 UNKNOWN Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation … May 25, 2026
CVE-2026-44598 UNKNOWN With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from … May 25, 2026
CVE-2026-43828 UNKNOWN Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. … May 25, 2026
CVE-2026-43827 UNKNOWN Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to … May 25, 2026
CVE-2026-24597 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5. May 25, 2026
CVE-2026-24574 MEDIUM 6.5 Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to … May 25, 2026
CVE-2026-24545 MEDIUM 4.3 Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3. May 25, 2026
CVE-2026-9498 MEDIUM 6.3 A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of … May 25, 2026
CVE-2026-9497 MEDIUM 6.3 A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This … May 25, 2026
CVE-2026-9486 MEDIUM 4.3 A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. … May 25, 2026
CVE-2026-9485 LOW 3.5 A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation … May 25, 2026
CVE-2026-9484 MEDIUM 6.3 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a … May 25, 2026