Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49608
Total
4010
Critical
14727
High
14463
Medium
CVE ID Severity Score Description Published
CVE-2026-5391 MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and … Aug 06, 2026
CVE-2026-5158 MEDIUM 6.4 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter … Aug 06, 2026
CVE-2026-57818 HIGH 8.1 A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple … Aug 06, 2026
CVE-2026-19035 HIGH 7.2 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument … Aug 06, 2026
CVE-2026-11983 MEDIUM 5.3 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 … Aug 06, 2026
CVE-2025-9266 MEDIUM 4.3 The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions … Aug 06, 2026
CVE-2025-15028 HIGH 7.2 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Aug 06, 2026
CVE-2026-66909 CRITICAL 9.8 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able … Aug 06, 2026
CVE-2026-65432 HIGH 7.5 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from … Aug 06, 2026
CVE-2026-64958 HIGH 7.5 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message … Aug 06, 2026
CVE-2026-57819 HIGH 7.5 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default … Aug 06, 2026
CVE-2026-57817 HIGH 8.1 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF … Aug 06, 2026
CVE-2026-54225 HIGH 7.5 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default … Aug 06, 2026
CVE-2026-19034 HIGH 7.2 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the … Aug 06, 2026
CVE-2026-55980 MEDIUM 5.5 A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition. Aug 06, 2026
CVE-2026-55979 MEDIUM 5.2 An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that … Aug 06, 2026
CVE-2026-55978 HIGH 8.4 An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's … Aug 06, 2026
CVE-2026-64640 MEDIUM 6.5 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view … Aug 06, 2026
CVE-2026-19022 MEDIUM 6.3 A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. … Aug 06, 2026
CVE-2026-64604 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When … Aug 06, 2026
CVE-2026-64603 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify … Aug 06, 2026
CVE-2026-64602 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung Chung: "spear_adc_probe() … Aug 06, 2026
CVE-2026-64601 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission In capture_urb_complete(), usb_anchor_urb() is … Aug 06, 2026
CVE-2026-64599 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_crypto_probe() When meson_allocate_chanlist() fails after a partial allocation, … Aug 06, 2026
CVE-2026-64598 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't … Aug 06, 2026