Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49732
Total
4014
Critical
14766
High
14490
Medium
CVE ID Severity Score Description Published
CVE-2026-7753 MEDIUM 6.5 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX … Aug 05, 2026
CVE-2026-71192 UNKNOWN In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can … Aug 05, 2026
CVE-2026-71191 UNKNOWN In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An … Aug 05, 2026
CVE-2026-71190 UNKNOWN In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows … Aug 05, 2026
CVE-2026-68074 UNKNOWN A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through … Aug 05, 2026
CVE-2026-68060 UNKNOWN A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through … Aug 05, 2026
CVE-2026-67589 UNKNOWN A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through … Aug 05, 2026
CVE-2026-67588 UNKNOWN A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through … Aug 05, 2026
CVE-2026-67551 UNKNOWN pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. … Aug 05, 2026
CVE-2026-67465 UNKNOWN A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through … Aug 05, 2026
CVE-2026-66839 MEDIUM 6.7 NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to … Aug 05, 2026
CVE-2026-66344 MEDIUM 6.7 NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute … Aug 05, 2026
CVE-2026-66273 UNKNOWN A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through … Aug 05, 2026
CVE-2026-66257 UNKNOWN A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through … Aug 05, 2026
CVE-2026-5062 MEDIUM 4.9 The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' … Aug 05, 2026
CVE-2026-55707 UNKNOWN In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another … Aug 05, 2026
CVE-2026-18903 MEDIUM 4.3 A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument … Aug 05, 2026
CVE-2026-18902 HIGH 7.2 A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the … Aug 05, 2026
CVE-2026-18322 HIGH 8.8 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to … Aug 05, 2026
CVE-2026-16143 HIGH 7.2 The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout … Aug 05, 2026
CVE-2026-15941 MEDIUM 6.5 The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler … Aug 05, 2026
CVE-2026-15918 HIGH 7.5 VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list … Aug 05, 2026
CVE-2026-11421 MEDIUM 6.5 The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in … Aug 05, 2026
CVE-2026-18901 HIGH 7.2 A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such … Aug 05, 2026
CVE-2026-18900 HIGH 7.2 A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation … Aug 05, 2026