Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19066 | MEDIUM | 4.3 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of … | Aug 06, 2026 |
| CVE-2026-19065 | MEDIUM | 6.3 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation … | Aug 06, 2026 |
| CVE-2026-19064 | MEDIUM | 4.3 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of … | Aug 06, 2026 |
| CVE-2026-19062 | HIGH | 7.3 | A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument … | Aug 06, 2026 |
| CVE-2026-19061 | LOW | 3.7 | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a … | Aug 06, 2026 |
| CVE-2026-19060 | MEDIUM | 5.3 | A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to … | Aug 06, 2026 |
| CVE-2026-19059 | LOW | 3.3 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The … | Aug 06, 2026 |
| CVE-2026-19058 | MEDIUM | 5.3 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in … | Aug 06, 2026 |
| CVE-2026-19054 | MEDIUM | 5.3 | A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File … | Aug 06, 2026 |
| CVE-2026-18487 | MEDIUM | 5.4 | A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the … | Aug 06, 2026 |
| CVE-2026-18367 | CRITICAL | 9.3 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home … | Aug 06, 2026 |
| CVE-2026-17032 | CRITICAL | 9.8 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates … | Aug 06, 2026 |
| CVE-2026-16620 | HIGH | 7.5 | The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, … | Aug 06, 2026 |
| CVE-2026-16619 | HIGH | 7.5 | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is … | Aug 06, 2026 |
| CVE-2026-16067 | MEDIUM | 5.3 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, … | Aug 06, 2026 |
| CVE-2026-15734 | UNKNOWN | — | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | Aug 06, 2026 |
| CVE-2026-15733 | UNKNOWN | — | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as … | Aug 06, 2026 |
| CVE-2026-15732 | UNKNOWN | — | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and … | Aug 06, 2026 |
| CVE-2026-15256 | MEDIUM | 4.8 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as … | Aug 06, 2026 |
| CVE-2026-15208 | MEDIUM | 5.3 | The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: … | Aug 06, 2026 |
| CVE-2026-15152 | MEDIUM | 5.3 | The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant … | Aug 06, 2026 |
| CVE-2026-15149 | MEDIUM | 5.3 | The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, … | Aug 06, 2026 |
| CVE-2026-15147 | MEDIUM | 5.3 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, … | Aug 06, 2026 |
| CVE-2026-14936 | MEDIUM | 5.3 | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before … | Aug 06, 2026 |
| CVE-2026-14842 | MEDIUM | 5.3 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to … | Aug 06, 2026 |