Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64564 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the … | Aug 04, 2026 |
| CVE-2026-64563 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a … | Aug 04, 2026 |
| CVE-2026-64562 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 … | Aug 04, 2026 |
| CVE-2026-64561 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" … | Aug 04, 2026 |
| CVE-2026-16623 | HIGH | 8.0 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite … | Aug 04, 2026 |
| CVE-2026-16618 | CRITICAL | 9.8 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the … | Aug 04, 2026 |
| CVE-2026-16548 | MEDIUM | 5.4 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, … | Aug 04, 2026 |
| CVE-2026-16547 | MEDIUM | 5.9 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor … | Aug 04, 2026 |
| CVE-2026-16546 | MEDIUM | 4.3 | The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that … | Aug 04, 2026 |
| CVE-2026-16536 | MEDIUM | 5.3 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers … | Aug 04, 2026 |
| CVE-2026-16296 | MEDIUM | 4.7 | The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to … | Aug 04, 2026 |
| CVE-2026-16295 | MEDIUM | 4.3 | The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such … | Aug 04, 2026 |
| CVE-2026-16293 | MEDIUM | 6.8 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users … | Aug 04, 2026 |
| CVE-2026-16070 | LOW | 2.7 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request … | Aug 04, 2026 |
| CVE-2026-16069 | MEDIUM | 6.8 | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and … | Aug 04, 2026 |
| CVE-2026-16068 | LOW | 3.5 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data … | Aug 04, 2026 |
| CVE-2026-16056 | MEDIUM | 4.3 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down … | Aug 04, 2026 |
| CVE-2026-16035 | MEDIUM | 4.3 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the … | Aug 04, 2026 |
| CVE-2026-15958 | CRITICAL | 9.3 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers … | Aug 04, 2026 |
| CVE-2026-15233 | MEDIUM | 4.8 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing … | Aug 04, 2026 |
| CVE-2026-14939 | MEDIUM | 6.8 | The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access … | Aug 04, 2026 |
| CVE-2026-14872 | MEDIUM | 6.8 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in … | Aug 04, 2026 |
| CVE-2026-14848 | MEDIUM | 5.4 | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, … | Aug 04, 2026 |
| CVE-2026-14824 | MEDIUM | 4.8 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, … | Aug 04, 2026 |
| CVE-2026-14816 | MEDIUM | 6.5 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices … | Aug 04, 2026 |