Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49232
Total
3944
Critical
14598
High
14363
Medium
CVE ID Severity Score Description Published
CVE-2026-15239 MEDIUM 5.3 The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator … Aug 07, 2026
CVE-2026-15211 MEDIUM 5.9 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed … Aug 07, 2026
CVE-2026-15148 MEDIUM 5.3 The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that … Aug 07, 2026
CVE-2026-12261 MEDIUM 5.3 A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such … Aug 07, 2026
CVE-2026-19196 HIGH 7.3 A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the … Aug 07, 2026
CVE-2026-16265 MEDIUM 6.5 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation … Aug 07, 2026
CVE-2026-16263 HIGH 8.8 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a … Aug 07, 2026
CVE-2026-16262 HIGH 7.5 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated … Aug 07, 2026
CVE-2026-16258 CRITICAL 9.8 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When … Aug 07, 2026
CVE-2026-16041 HIGH 7.5 The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to … Aug 07, 2026
CVE-2026-16039 MEDIUM 6.5 The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to … Aug 07, 2026
CVE-2026-16038 CRITICAL 9.1 The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of … Aug 07, 2026
CVE-2026-16030 HIGH 8.1 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated … Aug 07, 2026
CVE-2026-15386 MEDIUM 5.4 The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds … Aug 07, 2026
CVE-2026-15361 HIGH 8.1 The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied … Aug 07, 2026
CVE-2026-15359 MEDIUM 6.5 The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's … Aug 07, 2026
CVE-2026-15245 MEDIUM 5.4 The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, … Aug 07, 2026
CVE-2026-15215 HIGH 8.8 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before … Aug 07, 2026
CVE-2026-15214 MEDIUM 4.3 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any … Aug 07, 2026
CVE-2026-15032 MEDIUM 6.1 The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store … Aug 07, 2026
CVE-2026-14943 HIGH 7.5 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated … Aug 07, 2026
CVE-2026-14331 MEDIUM 6.1 The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site … Aug 07, 2026
CVE-2026-14205 CRITICAL 9.8 The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from … Aug 07, 2026
CVE-2026-49005 LOW 2.4 The root password hash of the device can be obtained through unencrypted information in the firmware. Aug 07, 2026
CVE-2026-19195 HIGH 7.8 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel … Aug 07, 2026