Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49732
Total
4014
Critical
14766
High
14490
Medium
CVE ID Severity Score Description Published
CVE-2026-64567 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free … Aug 05, 2026
CVE-2026-64566 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag … Aug 05, 2026
CVE-2026-61486 CRITICAL 9.8 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we … Aug 05, 2026
CVE-2026-61485 HIGH 7.5 ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project … Aug 05, 2026
CVE-2026-61484 CRITICAL 9.8 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, … Aug 05, 2026
CVE-2026-61483 UNKNOWN ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do … Aug 05, 2026
CVE-2026-5651 MEDIUM 4.9 The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, … Aug 05, 2026
CVE-2026-5581 CRITICAL 9.1 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This … Aug 05, 2026
CVE-2026-5116 MEDIUM 4.4 The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. … Aug 05, 2026
CVE-2026-5108 MEDIUM 4.4 The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, … Aug 05, 2026
CVE-2026-59675 HIGH 7.5 When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because … Aug 05, 2026
CVE-2026-55998 MEDIUM 5.3 The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, … Aug 05, 2026
CVE-2026-55997 HIGH 8.8 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, … Aug 05, 2026
CVE-2026-55996 MEDIUM 4.3 A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use … Aug 05, 2026
CVE-2026-55747 MEDIUM 6.8 The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded … Aug 05, 2026
CVE-2026-55739 HIGH 8.3 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, … Aug 05, 2026
CVE-2026-54418 HIGH 8.1 Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, … Aug 05, 2026
CVE-2026-54416 HIGH 7.2 Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 … Aug 05, 2026
CVE-2026-4431 CRITICAL 9.1 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in … Aug 05, 2026
CVE-2026-18881 HIGH 7.5 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX … Aug 05, 2026
CVE-2026-17532 MEDIUM 6.1 The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is … Aug 05, 2026
CVE-2026-17505 MEDIUM 6.1 The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, … Aug 05, 2026
CVE-2026-15281 MEDIUM 6.5 The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up … Aug 05, 2026
CVE-2026-12000 HIGH 7.5 The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core … Aug 05, 2026
CVE-2026-11977 MEDIUM 6.5 The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the … Aug 05, 2026