Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49358
Total
3967
Critical
14633
High
14397
Medium
CVE ID Severity Score Description Published
CVE-2026-14831 MEDIUM 5.3 The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart … Aug 06, 2026
CVE-2026-14812 CRITICAL 10.0 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote … Aug 06, 2026
CVE-2026-14306 MEDIUM 4.3 The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access … Aug 06, 2026
CVE-2026-14225 LOW 2.7 The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of … Aug 06, 2026
CVE-2026-13399 HIGH 7.5 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass … Aug 06, 2026
CVE-2026-13342 MEDIUM 5.3 The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to … Aug 06, 2026
CVE-2026-12901 MEDIUM 5.9 The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks … Aug 06, 2026
CVE-2026-12584 HIGH 7.5 The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its … Aug 06, 2026
CVE-2026-12501 MEDIUM 5.3 The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, … Aug 06, 2026
CVE-2026-11976 CRITICAL 10.0 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a … Aug 06, 2026
CVE-2026-11803 HIGH 7.8 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause … Aug 06, 2026
CVE-2026-11361 MEDIUM 5.9 The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users … Aug 06, 2026
CVE-2026-10599 HIGH 7.5 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, … Aug 06, 2026
CVE-2026-10524 HIGH 7.5 The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart … Aug 06, 2026
CVE-2025-6508 MEDIUM 4.3 The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions … Aug 06, 2026
CVE-2025-15674 LOW 2.7 The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST … Aug 06, 2026
CVE-2025-14561 CRITICAL 9.0 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke … Aug 06, 2026
CVE-2025-12317 MEDIUM 5.0 When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that … Aug 06, 2026
CVE-2024-6541 MEDIUM 6.8 The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially … Aug 06, 2026
CVE-2024-39024 HIGH 8.8 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. Aug 06, 2026
CVE-2026-68750 UNKNOWN Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat … Aug 06, 2026
CVE-2026-68749 UNKNOWN Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS … Aug 06, 2026
CVE-2026-68747 UNKNOWN Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote … Aug 06, 2026
CVE-2026-66843 UNKNOWN Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their … Aug 06, 2026
CVE-2026-66829 UNKNOWN URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page … Aug 06, 2026