Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-21548 HIGH 7.5 In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed. Aug 03, 2026
CVE-2026-18593 MEDIUM 5.6 A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management … Aug 03, 2026
CVE-2026-18592 MEDIUM 4.7 A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email … Aug 03, 2026
CVE-2026-18591 LOW 2.1 A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component … Aug 03, 2026
CVE-2026-18590 MEDIUM 6.3 A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation … Aug 03, 2026
CVE-2026-12259 MEDIUM 5.3 In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This … Aug 03, 2026
CVE-2026-9593 MEDIUM 6.7 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing … Aug 03, 2026
CVE-2026-4793 HIGH 7.3 An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. Aug 03, 2026
CVE-2026-18589 CRITICAL 9.8 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in … Aug 03, 2026
CVE-2026-18588 CRITICAL 9.8 A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads … Aug 03, 2026
CVE-2026-18587 HIGH 7.5 A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of … Aug 03, 2026
CVE-2026-16572 HIGH 8.6 The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing … Aug 03, 2026
CVE-2026-16565 MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users … Aug 03, 2026
CVE-2026-16564 MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status … Aug 03, 2026
CVE-2026-16563 MEDIUM 6.5 The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, … Aug 03, 2026
CVE-2026-16539 HIGH 8.1 The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating … Aug 03, 2026
CVE-2026-16534 CRITICAL 9.1 The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a … Aug 03, 2026
CVE-2026-16532 CRITICAL 9.1 The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated … Aug 03, 2026
CVE-2026-16300 CRITICAL 9.8 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including … Aug 03, 2026
CVE-2026-16297 MEDIUM 4.1 The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP … Aug 03, 2026
CVE-2026-16289 MEDIUM 4.3 The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a … Aug 03, 2026
CVE-2026-16276 UNKNOWN The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users … Aug 03, 2026
CVE-2026-16274 UNKNOWN The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing … Aug 03, 2026
CVE-2026-16250 UNKNOWN The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users … Aug 03, 2026
CVE-2026-16060 UNKNOWN The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable … Aug 03, 2026