Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49358
Total
3967
Critical
14633
High
14397
Medium
CVE ID Severity Score Description Published
CVE-2026-19066 MEDIUM 4.3 A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of … Aug 06, 2026
CVE-2026-19065 MEDIUM 6.3 A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation … Aug 06, 2026
CVE-2026-19064 MEDIUM 4.3 A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of … Aug 06, 2026
CVE-2026-19062 HIGH 7.3 A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument … Aug 06, 2026
CVE-2026-19061 LOW 3.7 A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a … Aug 06, 2026
CVE-2026-19060 MEDIUM 5.3 A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to … Aug 06, 2026
CVE-2026-19059 LOW 3.3 A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The … Aug 06, 2026
CVE-2026-19058 MEDIUM 5.3 A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in … Aug 06, 2026
CVE-2026-19054 MEDIUM 5.3 A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File … Aug 06, 2026
CVE-2026-18487 MEDIUM 5.4 A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the … Aug 06, 2026
CVE-2026-18367 CRITICAL 9.3 A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home … Aug 06, 2026
CVE-2026-17032 CRITICAL 9.8 Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates … Aug 06, 2026
CVE-2026-16620 HIGH 7.5 The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, … Aug 06, 2026
CVE-2026-16619 HIGH 7.5 The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is … Aug 06, 2026
CVE-2026-16067 MEDIUM 5.3 The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, … Aug 06, 2026
CVE-2026-15734 UNKNOWN A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. Aug 06, 2026
CVE-2026-15733 UNKNOWN A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as … Aug 06, 2026
CVE-2026-15732 UNKNOWN A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and … Aug 06, 2026
CVE-2026-15256 MEDIUM 4.8 The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as … Aug 06, 2026
CVE-2026-15208 MEDIUM 5.3 The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: … Aug 06, 2026
CVE-2026-15152 MEDIUM 5.3 The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant … Aug 06, 2026
CVE-2026-15149 MEDIUM 5.3 The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, … Aug 06, 2026
CVE-2026-15147 MEDIUM 5.3 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, … Aug 06, 2026
CVE-2026-14936 MEDIUM 5.3 The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before … Aug 06, 2026
CVE-2026-14842 MEDIUM 5.3 The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to … Aug 06, 2026