Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49177
Total
3940
Critical
14579
High
14345
Medium
CVE ID Severity Score Description Published
CVE-2026-16594 UNKNOWN The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated … Aug 08, 2026
CVE-2026-16590 UNKNOWN The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated … Aug 08, 2026
CVE-2026-16589 UNKNOWN The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of … Aug 08, 2026
CVE-2026-16578 UNKNOWN The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on … Aug 08, 2026
CVE-2026-16574 UNKNOWN The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before … Aug 08, 2026
CVE-2026-16562 UNKNOWN The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a … Aug 08, 2026
CVE-2026-16559 UNKNOWN The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by … Aug 08, 2026
CVE-2026-16558 UNKNOWN The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does … Aug 08, 2026
CVE-2026-16535 UNKNOWN The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to … Aug 08, 2026
CVE-2026-16282 UNKNOWN The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to … Aug 08, 2026
CVE-2026-16269 UNKNOWN The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling … Aug 08, 2026
CVE-2026-16267 UNKNOWN The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers … Aug 08, 2026
CVE-2026-14526 CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due … Aug 08, 2026
CVE-2026-18988 MEDIUM 6.4 The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This … Aug 08, 2026
CVE-2026-13505 UNKNOWN In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the … Aug 08, 2026
CVE-2026-8798 UNKNOWN In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any … Aug 08, 2026
CVE-2026-52880 HIGH 7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both … Aug 07, 2026
CVE-2026-52879 HIGH 7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every … Aug 07, 2026
CVE-2026-52878 HIGH 7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction … Aug 07, 2026
CVE-2026-49343 MEDIUM 5.9 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw … Aug 07, 2026
CVE-2026-48122 UNKNOWN Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version … Aug 07, 2026
CVE-2026-48120 HIGH 8.6 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to … Aug 07, 2026
CVE-2026-48047 UNKNOWN XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, … Aug 07, 2026
CVE-2026-48026 HIGH 8.7 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of … Aug 07, 2026
CVE-2026-47249 HIGH 7.5 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A … Aug 07, 2026