Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-65546 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | Aug 06, 2026 |
| CVE-2026-65545 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | Aug 06, 2026 |
| CVE-2026-65544 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | Aug 06, 2026 |
| CVE-2026-65543 | HIGH | 7.5 | Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | Aug 06, 2026 |
| CVE-2026-65542 | HIGH | 8.8 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | Aug 06, 2026 |
| CVE-2026-65541 | HIGH | 7.3 | Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | Aug 06, 2026 |
| CVE-2026-65523 | HIGH | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | Aug 06, 2026 |
| CVE-2026-65520 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | Aug 06, 2026 |
| CVE-2026-65517 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | Aug 06, 2026 |
| CVE-2026-65515 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | Aug 06, 2026 |
| CVE-2026-65513 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | Aug 06, 2026 |
| CVE-2026-65509 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | Aug 06, 2026 |
| CVE-2026-65508 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | Aug 06, 2026 |
| CVE-2026-65507 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | Aug 06, 2026 |
| CVE-2026-65504 | HIGH | 7.5 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | Aug 06, 2026 |
| CVE-2026-65502 | MEDIUM | 5.3 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | Aug 06, 2026 |
| CVE-2026-61982 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | Aug 06, 2026 |
| CVE-2026-61964 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | Aug 06, 2026 |
| CVE-2026-61963 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | Aug 06, 2026 |
| CVE-2026-61961 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | Aug 06, 2026 |
| CVE-2026-61959 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | Aug 06, 2026 |
| CVE-2026-54489 | CRITICAL | 9.1 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit … | Aug 06, 2026 |
| CVE-2026-53976 | CRITICAL | 9.1 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by … | Aug 06, 2026 |
| CVE-2026-53975 | CRITICAL | 9.8 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the … | Aug 06, 2026 |
| CVE-2026-34502 | HIGH | 7.5 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | Aug 06, 2026 |