Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-21548 | HIGH | 7.5 | In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed. | Aug 03, 2026 |
| CVE-2026-18593 | MEDIUM | 5.6 | A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management … | Aug 03, 2026 |
| CVE-2026-18592 | MEDIUM | 4.7 | A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email … | Aug 03, 2026 |
| CVE-2026-18591 | LOW | 2.1 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component … | Aug 03, 2026 |
| CVE-2026-18590 | MEDIUM | 6.3 | A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation … | Aug 03, 2026 |
| CVE-2026-12259 | MEDIUM | 5.3 | In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This … | Aug 03, 2026 |
| CVE-2026-9593 | MEDIUM | 6.7 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing … | Aug 03, 2026 |
| CVE-2026-4793 | HIGH | 7.3 | An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. | Aug 03, 2026 |
| CVE-2026-18589 | CRITICAL | 9.8 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in … | Aug 03, 2026 |
| CVE-2026-18588 | CRITICAL | 9.8 | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads … | Aug 03, 2026 |
| CVE-2026-18587 | HIGH | 7.5 | A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of … | Aug 03, 2026 |
| CVE-2026-16572 | HIGH | 8.6 | The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing … | Aug 03, 2026 |
| CVE-2026-16565 | MEDIUM | 4.3 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users … | Aug 03, 2026 |
| CVE-2026-16564 | MEDIUM | 4.3 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status … | Aug 03, 2026 |
| CVE-2026-16563 | MEDIUM | 6.5 | The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, … | Aug 03, 2026 |
| CVE-2026-16539 | HIGH | 8.1 | The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating … | Aug 03, 2026 |
| CVE-2026-16534 | CRITICAL | 9.1 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a … | Aug 03, 2026 |
| CVE-2026-16532 | CRITICAL | 9.1 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated … | Aug 03, 2026 |
| CVE-2026-16300 | CRITICAL | 9.8 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including … | Aug 03, 2026 |
| CVE-2026-16297 | MEDIUM | 4.1 | The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP … | Aug 03, 2026 |
| CVE-2026-16289 | MEDIUM | 4.3 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a … | Aug 03, 2026 |
| CVE-2026-16276 | UNKNOWN | — | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users … | Aug 03, 2026 |
| CVE-2026-16274 | UNKNOWN | — | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing … | Aug 03, 2026 |
| CVE-2026-16250 | UNKNOWN | — | The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users … | Aug 03, 2026 |
| CVE-2026-16060 | UNKNOWN | — | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable … | Aug 03, 2026 |