Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-16057 UNKNOWN The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by … Aug 03, 2026
CVE-2026-15931 MEDIUM 6.1 The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when … Aug 03, 2026
CVE-2026-15930 CRITICAL 9.4 The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID … Aug 03, 2026
CVE-2026-15383 MEDIUM 6.1 The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST … Aug 03, 2026
CVE-2026-15260 MEDIUM 4.3 The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users … Aug 03, 2026
CVE-2026-15254 MEDIUM 6.5 The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails … Aug 03, 2026
CVE-2026-15231 UNKNOWN The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing … Aug 03, 2026
CVE-2026-14557 UNKNOWN The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated … Aug 03, 2026
CVE-2026-13340 MEDIUM 6.1 The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and … Aug 03, 2026
CVE-2026-12965 CRITICAL 9.1 The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, … Aug 03, 2026
CVE-2026-12872 UNKNOWN The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, … Aug 03, 2026
CVE-2025-15673 UNKNOWN The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a … Aug 03, 2026
CVE-2025-15672 UNKNOWN The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject … Aug 03, 2026
CVE-2026-6695 MEDIUM 5.5 A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro … Aug 03, 2026
CVE-2026-6694 MEDIUM 5.5 A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing … Aug 03, 2026
CVE-2026-18585 MEDIUM 4.3 A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is … Aug 03, 2026
CVE-2026-18584 MEDIUM 5.4 A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the … Aug 03, 2026
CVE-2026-18583 MEDIUM 5.3 A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS … Aug 03, 2026
CVE-2026-14682 UNKNOWN In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java … Aug 03, 2026
CVE-2026-13586 UNKNOWN In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before … Aug 03, 2026
CVE-2026-13506 UNKNOWN In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, … Aug 03, 2026
CVE-2026-12860 UNKNOWN In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for … Aug 03, 2026
CVE-2026-12852 UNKNOWN In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. Aug 03, 2026
CVE-2026-12817 UNKNOWN In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS … Aug 03, 2026
CVE-2026-12816 UNKNOWN In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before … Aug 03, 2026