Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-13154 HIGH 7.5 The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of … Aug 06, 2026
CVE-2026-13153 HIGH 7.5 The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product … Aug 06, 2026
CVE-2026-12713 CRITICAL 9.1 The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing … Aug 06, 2026
CVE-2026-11588 MEDIUM 6.1 The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation … Aug 06, 2026
CVE-2025-15678 MEDIUM 6.1 The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author … Aug 06, 2026
CVE-2026-19000 HIGH 7.3 A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat … Aug 06, 2026
CVE-2026-18998 MEDIUM 6.3 A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing … Aug 06, 2026
CVE-2026-18997 MEDIUM 6.3 A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command … Aug 06, 2026
CVE-2026-15459 HIGH 8.1 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected … Aug 06, 2026
CVE-2026-18996 MEDIUM 6.3 A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command … Aug 06, 2026
CVE-2026-18995 MEDIUM 4.3 A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This … Aug 06, 2026
CVE-2026-18993 MEDIUM 6.3 A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component … Aug 06, 2026
CVE-2026-18992 MEDIUM 6.3 A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review … Aug 06, 2026
CVE-2026-18909 MEDIUM 4.7 A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce … Aug 06, 2026
CVE-2026-18325 HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record … Aug 06, 2026
CVE-2026-16636 HIGH 7.2 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site … Aug 06, 2026
CVE-2026-15991 HIGH 8.8 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions … Aug 06, 2026
CVE-2026-18991 HIGH 7.3 A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. … Aug 06, 2026
CVE-2026-18990 HIGH 7.3 A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation … Aug 06, 2026
CVE-2026-18980 MEDIUM 6.3 A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. … Aug 06, 2026
CVE-2026-18976 MEDIUM 6.3 A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This … Aug 06, 2026
CVE-2026-18974 MEDIUM 5.3 A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The … Aug 06, 2026
CVE-2026-18973 HIGH 7.3 A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component … Aug 06, 2026
CVE-2026-67873 CRITICAL 9.8 A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment … Aug 06, 2026
CVE-2026-67872 HIGH 7.5 An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling Aug 06, 2026