Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13154 | HIGH | 7.5 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of … | Aug 06, 2026 |
| CVE-2026-13153 | HIGH | 7.5 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product … | Aug 06, 2026 |
| CVE-2026-12713 | CRITICAL | 9.1 | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing … | Aug 06, 2026 |
| CVE-2026-11588 | MEDIUM | 6.1 | The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation … | Aug 06, 2026 |
| CVE-2025-15678 | MEDIUM | 6.1 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author … | Aug 06, 2026 |
| CVE-2026-19000 | HIGH | 7.3 | A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat … | Aug 06, 2026 |
| CVE-2026-18998 | MEDIUM | 6.3 | A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing … | Aug 06, 2026 |
| CVE-2026-18997 | MEDIUM | 6.3 | A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command … | Aug 06, 2026 |
| CVE-2026-15459 | HIGH | 8.1 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected … | Aug 06, 2026 |
| CVE-2026-18996 | MEDIUM | 6.3 | A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command … | Aug 06, 2026 |
| CVE-2026-18995 | MEDIUM | 4.3 | A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This … | Aug 06, 2026 |
| CVE-2026-18993 | MEDIUM | 6.3 | A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component … | Aug 06, 2026 |
| CVE-2026-18992 | MEDIUM | 6.3 | A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review … | Aug 06, 2026 |
| CVE-2026-18909 | MEDIUM | 4.7 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce … | Aug 06, 2026 |
| CVE-2026-18325 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record … | Aug 06, 2026 |
| CVE-2026-16636 | HIGH | 7.2 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site … | Aug 06, 2026 |
| CVE-2026-15991 | HIGH | 8.8 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions … | Aug 06, 2026 |
| CVE-2026-18991 | HIGH | 7.3 | A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. … | Aug 06, 2026 |
| CVE-2026-18990 | HIGH | 7.3 | A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation … | Aug 06, 2026 |
| CVE-2026-18980 | MEDIUM | 6.3 | A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. … | Aug 06, 2026 |
| CVE-2026-18976 | MEDIUM | 6.3 | A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This … | Aug 06, 2026 |
| CVE-2026-18974 | MEDIUM | 5.3 | A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The … | Aug 06, 2026 |
| CVE-2026-18973 | HIGH | 7.3 | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component … | Aug 06, 2026 |
| CVE-2026-67873 | CRITICAL | 9.8 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment … | Aug 06, 2026 |
| CVE-2026-67872 | HIGH | 7.5 | An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling | Aug 06, 2026 |