Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2023-7355 UNKNOWN Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. Aug 06, 2026
CVE-2023-7354 UNKNOWN Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. Aug 06, 2026
CVE-2023-7353 UNKNOWN Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. Aug 06, 2026
CVE-2026-19007 MEDIUM 6.3 A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege … Aug 06, 2026
CVE-2026-19006 MEDIUM 6.3 A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The … Aug 06, 2026
CVE-2026-19005 MEDIUM 6.3 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component Child-Agent Creation. Performing … Aug 06, 2026
CVE-2026-18967 MEDIUM 6.4 A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the … Aug 06, 2026
CVE-2026-18510 HIGH 7.2 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in … Aug 06, 2026
CVE-2026-18400 MEDIUM 6.4 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta … Aug 06, 2026
CVE-2026-18395 MEDIUM 5.4 The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, … Aug 06, 2026
CVE-2026-18050 HIGH 7.5 The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated … Aug 06, 2026
CVE-2026-16954 MEDIUM 6.5 The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users … Aug 06, 2026
CVE-2026-16734 HIGH 7.5 The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by … Aug 06, 2026
CVE-2026-16537 MEDIUM 5.4 The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users … Aug 06, 2026
CVE-2026-16290 MEDIUM 5.3 The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing … Aug 06, 2026
CVE-2026-16268 HIGH 8.2 The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated … Aug 06, 2026
CVE-2026-16065 MEDIUM 6.5 The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL … Aug 06, 2026
CVE-2026-16054 CRITICAL 9.1 The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is … Aug 06, 2026
CVE-2026-14829 HIGH 8.2 The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying … Aug 06, 2026
CVE-2026-14547 MEDIUM 5.3 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request … Aug 06, 2026
CVE-2026-14314 MEDIUM 5.3 The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, … Aug 06, 2026
CVE-2026-14313 MEDIUM 5.3 PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no … Aug 06, 2026
CVE-2026-14240 MEDIUM 5.3 The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing … Aug 06, 2026
CVE-2026-14204 MEDIUM 6.5 The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user … Aug 06, 2026
CVE-2026-13703 MEDIUM 5.4 The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user … Aug 06, 2026