Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49232
Total
3944
Critical
14598
High
14363
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15239 | MEDIUM | 5.3 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator … | Aug 07, 2026 |
| CVE-2026-15211 | MEDIUM | 5.9 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed … | Aug 07, 2026 |
| CVE-2026-15148 | MEDIUM | 5.3 | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that … | Aug 07, 2026 |
| CVE-2026-12261 | MEDIUM | 5.3 | A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such … | Aug 07, 2026 |
| CVE-2026-19196 | HIGH | 7.3 | A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the … | Aug 07, 2026 |
| CVE-2026-16265 | MEDIUM | 6.5 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation … | Aug 07, 2026 |
| CVE-2026-16263 | HIGH | 8.8 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a … | Aug 07, 2026 |
| CVE-2026-16262 | HIGH | 7.5 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated … | Aug 07, 2026 |
| CVE-2026-16258 | CRITICAL | 9.8 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When … | Aug 07, 2026 |
| CVE-2026-16041 | HIGH | 7.5 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to … | Aug 07, 2026 |
| CVE-2026-16039 | MEDIUM | 6.5 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to … | Aug 07, 2026 |
| CVE-2026-16038 | CRITICAL | 9.1 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of … | Aug 07, 2026 |
| CVE-2026-16030 | HIGH | 8.1 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated … | Aug 07, 2026 |
| CVE-2026-15386 | MEDIUM | 5.4 | The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds … | Aug 07, 2026 |
| CVE-2026-15361 | HIGH | 8.1 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied … | Aug 07, 2026 |
| CVE-2026-15359 | MEDIUM | 6.5 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's … | Aug 07, 2026 |
| CVE-2026-15245 | MEDIUM | 5.4 | The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, … | Aug 07, 2026 |
| CVE-2026-15215 | HIGH | 8.8 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before … | Aug 07, 2026 |
| CVE-2026-15214 | MEDIUM | 4.3 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any … | Aug 07, 2026 |
| CVE-2026-15032 | MEDIUM | 6.1 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store … | Aug 07, 2026 |
| CVE-2026-14943 | HIGH | 7.5 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated … | Aug 07, 2026 |
| CVE-2026-14331 | MEDIUM | 6.1 | The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site … | Aug 07, 2026 |
| CVE-2026-14205 | CRITICAL | 9.8 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from … | Aug 07, 2026 |
| CVE-2026-49005 | LOW | 2.4 | The root password hash of the device can be obtained through unencrypted information in the firmware. | Aug 07, 2026 |
| CVE-2026-19195 | HIGH | 7.8 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel … | Aug 07, 2026 |