Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-15206 UNKNOWN The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an … Aug 02, 2026
CVE-2026-15151 UNKNOWN The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the … Aug 02, 2026
CVE-2026-14938 UNKNOWN The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user … Aug 02, 2026
CVE-2026-14920 UNKNOWN ## Summary Aug 02, 2026
CVE-2026-14864 UNKNOWN The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the … Aug 02, 2026
CVE-2026-14841 UNKNOWN The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an … Aug 02, 2026
CVE-2026-14817 UNKNOWN The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library … Aug 02, 2026
CVE-2026-13389 UNKNOWN The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete … Aug 02, 2026
CVE-2026-12586 UNKNOWN The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing … Aug 02, 2026
CVE-2026-11872 UNKNOWN The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates … Aug 02, 2026
CVE-2025-15675 UNKNOWN The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, … Aug 02, 2026
CVE-2026-9335 MEDIUM 6.5 A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` … Aug 02, 2026
CVE-2026-8457 CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to … Aug 02, 2026
CVE-2026-18352 HIGH 7.5 The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. … Aug 02, 2026
CVE-2026-13339 HIGH 7.5 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes … Aug 02, 2026
CVE-2026-17002 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 01, 2026
CVE-2026-18556 UNKNOWN Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. Aug 01, 2026
CVE-2026-55735 UNKNOWN Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes … Aug 01, 2026
CVE-2026-55734 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is … Aug 01, 2026
CVE-2026-55733 UNKNOWN Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission … Aug 01, 2026
CVE-2026-54894 UNKNOWN Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection … Aug 01, 2026
CVE-2026-67355 MEDIUM 5.9 guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers … Aug 01, 2026
CVE-2026-67354 MEDIUM 5.9 guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the … Aug 01, 2026
CVE-2026-67353 MEDIUM 5.3 guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can … Aug 01, 2026
CVE-2026-67352 HIGH 7.6 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS … Aug 01, 2026