Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19796 | HIGH | 7.2 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up … | Sep 01, 2026 |
| CVE-2026-19573 | HIGH | 7.2 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 … | Sep 01, 2026 |
| CVE-2026-18752 | MEDIUM | 6.5 | The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to … | Sep 01, 2026 |
| CVE-2026-17589 | MEDIUM | 4.9 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and … | Sep 01, 2026 |
| CVE-2026-16787 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, … | Sep 01, 2026 |
| CVE-2026-13203 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section … | Sep 01, 2026 |
| CVE-2026-12747 | MEDIUM | 6.4 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, … | Sep 01, 2026 |
| CVE-2026-82749 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading … | Sep 01, 2026 |
| CVE-2026-82748 | UNKNOWN | — | Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies … | Sep 01, 2026 |
| CVE-2026-82746 | UNKNOWN | — | Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as … | Sep 01, 2026 |
| CVE-2026-82745 | UNKNOWN | — | Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because … | Sep 01, 2026 |
| CVE-2026-82744 | UNKNOWN | — | Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run … | Sep 01, 2026 |
| CVE-2026-82743 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. … | Sep 01, 2026 |
| CVE-2026-82742 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime … | Sep 01, 2026 |
| CVE-2026-82741 | UNKNOWN | — | Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses … | Sep 01, 2026 |
| CVE-2026-82740 | UNKNOWN | — | Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting invalid input pass … | Sep 01, 2026 |
| CVE-2026-82739 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its … | Sep 01, 2026 |
| CVE-2026-82738 | UNKNOWN | — | Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 … | Sep 01, 2026 |
| CVE-2026-82737 | UNKNOWN | — | Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector … | Sep 01, 2026 |
| CVE-2026-82736 | UNKNOWN | — | Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. … | Sep 01, 2026 |
| CVE-2026-82735 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should … | Sep 01, 2026 |
| CVE-2026-82734 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints … | Sep 01, 2026 |
| CVE-2026-19032 | MEDIUM | 5.3 | jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new … | Sep 01, 2026 |
| CVE-2026-82733 | UNKNOWN | — | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response … | Sep 01, 2026 |
| CVE-2026-82732 | UNKNOWN | — | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler … | Sep 01, 2026 |