Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14831 | MEDIUM | 5.3 | The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart … | Aug 06, 2026 |
| CVE-2026-14812 | CRITICAL | 10.0 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote … | Aug 06, 2026 |
| CVE-2026-14306 | MEDIUM | 4.3 | The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access … | Aug 06, 2026 |
| CVE-2026-14225 | LOW | 2.7 | The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of … | Aug 06, 2026 |
| CVE-2026-13399 | HIGH | 7.5 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass … | Aug 06, 2026 |
| CVE-2026-13342 | MEDIUM | 5.3 | The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to … | Aug 06, 2026 |
| CVE-2026-12901 | MEDIUM | 5.9 | The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks … | Aug 06, 2026 |
| CVE-2026-12584 | HIGH | 7.5 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its … | Aug 06, 2026 |
| CVE-2026-12501 | MEDIUM | 5.3 | The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, … | Aug 06, 2026 |
| CVE-2026-11976 | CRITICAL | 10.0 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a … | Aug 06, 2026 |
| CVE-2026-11803 | HIGH | 7.8 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause … | Aug 06, 2026 |
| CVE-2026-11361 | MEDIUM | 5.9 | The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users … | Aug 06, 2026 |
| CVE-2026-10599 | HIGH | 7.5 | The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, … | Aug 06, 2026 |
| CVE-2026-10524 | HIGH | 7.5 | The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart … | Aug 06, 2026 |
| CVE-2025-6508 | MEDIUM | 4.3 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions … | Aug 06, 2026 |
| CVE-2025-15674 | LOW | 2.7 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST … | Aug 06, 2026 |
| CVE-2025-14561 | CRITICAL | 9.0 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke … | Aug 06, 2026 |
| CVE-2025-12317 | MEDIUM | 5.0 | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that … | Aug 06, 2026 |
| CVE-2024-6541 | MEDIUM | 6.8 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially … | Aug 06, 2026 |
| CVE-2024-39024 | HIGH | 8.8 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | Aug 06, 2026 |
| CVE-2026-68750 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat … | Aug 06, 2026 |
| CVE-2026-68749 | UNKNOWN | — | Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS … | Aug 06, 2026 |
| CVE-2026-68747 | UNKNOWN | — | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote … | Aug 06, 2026 |
| CVE-2026-66843 | UNKNOWN | — | Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their … | Aug 06, 2026 |
| CVE-2026-66829 | UNKNOWN | — | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page … | Aug 06, 2026 |