Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67356 | HIGH | 8.8 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA … | Aug 02, 2026 |
| CVE-2025-71401 | MEDIUM | 5.9 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to … | Aug 02, 2026 |
| CVE-2025-71400 | HIGH | 7.1 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys … | Aug 02, 2026 |
| CVE-2025-71399 | HIGH | 8.6 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, … | Aug 02, 2026 |
| CVE-2026-12231 | MEDIUM | 6.4 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and … | Aug 02, 2026 |
| CVE-2026-18573 | MEDIUM | 6.5 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm … | Aug 02, 2026 |
| CVE-2026-18572 | MEDIUM | 6.5 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A … | Aug 02, 2026 |
| CVE-2026-18571 | MEDIUM | 6.6 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator … | Aug 02, 2026 |
| CVE-2026-18570 | MEDIUM | 5.4 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and … | Aug 02, 2026 |
| CVE-2026-16540 | UNKNOWN | — | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to … | Aug 02, 2026 |
| CVE-2026-16292 | UNKNOWN | — | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to … | Aug 02, 2026 |
| CVE-2026-16291 | UNKNOWN | — | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such … | Aug 02, 2026 |
| CVE-2026-16285 | UNKNOWN | — | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download … | Aug 02, 2026 |
| CVE-2026-16273 | UNKNOWN | — | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users … | Aug 02, 2026 |
| CVE-2026-16261 | UNKNOWN | — | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from … | Aug 02, 2026 |
| CVE-2026-16256 | UNKNOWN | — | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create … | Aug 02, 2026 |
| CVE-2026-16064 | UNKNOWN | — | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking … | Aug 02, 2026 |
| CVE-2026-16063 | UNKNOWN | — | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before … | Aug 02, 2026 |
| CVE-2026-16062 | UNKNOWN | — | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, … | Aug 02, 2026 |
| CVE-2026-16042 | UNKNOWN | — | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush … | Aug 02, 2026 |
| CVE-2026-15939 | UNKNOWN | — | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front … | Aug 02, 2026 |
| CVE-2026-15385 | UNKNOWN | — | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; … | Aug 02, 2026 |
| CVE-2026-15248 | UNKNOWN | — | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users … | Aug 02, 2026 |
| CVE-2026-15241 | UNKNOWN | — | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated … | Aug 02, 2026 |
| CVE-2026-15236 | UNKNOWN | — | The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing … | Aug 02, 2026 |