Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50089
Total
4047
Critical
14897
High
14637
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16069 | MEDIUM | 6.8 | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and … | Aug 04, 2026 |
| CVE-2026-16068 | LOW | 3.5 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data … | Aug 04, 2026 |
| CVE-2026-16056 | MEDIUM | 4.3 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down … | Aug 04, 2026 |
| CVE-2026-16035 | MEDIUM | 4.3 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the … | Aug 04, 2026 |
| CVE-2026-15958 | CRITICAL | 9.3 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers … | Aug 04, 2026 |
| CVE-2026-15233 | MEDIUM | 4.8 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing … | Aug 04, 2026 |
| CVE-2026-14939 | MEDIUM | 6.8 | The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access … | Aug 04, 2026 |
| CVE-2026-14872 | MEDIUM | 6.8 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in … | Aug 04, 2026 |
| CVE-2026-14848 | MEDIUM | 5.4 | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, … | Aug 04, 2026 |
| CVE-2026-14824 | MEDIUM | 4.8 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, … | Aug 04, 2026 |
| CVE-2026-14816 | MEDIUM | 6.5 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices … | Aug 04, 2026 |
| CVE-2026-12698 | MEDIUM | 4.3 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with … | Aug 04, 2026 |
| CVE-2026-11366 | LOW | 3.7 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before … | Aug 04, 2026 |
| CVE-2026-10526 | MEDIUM | 5.8 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site … | Aug 04, 2026 |
| CVE-2026-68744 | LOW | 3.3 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the … | Aug 04, 2026 |
| CVE-2026-18739 | LOW | 2.5 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application … | Aug 04, 2026 |
| CVE-2026-18569 | LOW | 3.7 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component … | Aug 04, 2026 |
| CVE-2026-16881 | UNKNOWN | — | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally … | Aug 04, 2026 |
| CVE-2026-42169 | HIGH | 7.3 | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading … | Aug 04, 2026 |
| CVE-2026-18723 | MEDIUM | 6.3 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey … | Aug 04, 2026 |
| CVE-2026-18722 | MEDIUM | 6.3 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. … | Aug 04, 2026 |
| CVE-2026-18721 | MEDIUM | 4.3 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO … | Aug 04, 2026 |
| CVE-2026-14818 | HIGH | 7.2 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, … | Aug 04, 2026 |
| CVE-2026-8508 | MEDIUM | 6.5 | An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass … | Aug 04, 2026 |
| CVE-2026-6837 | HIGH | 7.2 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges … | Aug 04, 2026 |