Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50169
Total
4054
Critical
14909
High
14667
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10773 | MEDIUM | 5.4 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type … | Aug 01, 2026 |
| CVE-2026-10772 | UNKNOWN | — | Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by … | Aug 01, 2026 |
| CVE-2025-71404 | UNKNOWN | — | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL … | Aug 01, 2026 |
| CVE-2025-71403 | HIGH | 7.1 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that … | Aug 01, 2026 |
| CVE-2025-71402 | UNKNOWN | — | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted … | Aug 01, 2026 |
| CVE-2026-18536 | UNKNOWN | — | Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The … | Aug 01, 2026 |
| CVE-2026-6453 | MEDIUM | 6.5 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input … | Aug 01, 2026 |
| CVE-2026-18435 | MEDIUM | 6.4 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all … | Aug 01, 2026 |
| CVE-2026-18344 | MEDIUM | 6.1 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. … | Aug 01, 2026 |
| CVE-2026-18062 | MEDIUM | 6.4 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content … | Aug 01, 2026 |
| CVE-2026-18059 | MEDIUM | 5.3 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … | Aug 01, 2026 |
| CVE-2026-17605 | MEDIUM | 6.6 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, … | Aug 01, 2026 |
| CVE-2026-17580 | MEDIUM | 6.5 | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is … | Aug 01, 2026 |
| CVE-2026-17571 | MEDIUM | 6.1 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in … | Aug 01, 2026 |
| CVE-2026-17555 | MEDIUM | 4.9 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This … | Aug 01, 2026 |
| CVE-2026-16685 | MEDIUM | 6.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due … | Aug 01, 2026 |
| CVE-2026-16684 | MEDIUM | 6.4 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, … | Aug 01, 2026 |
| CVE-2026-16635 | HIGH | 8.8 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` … | Aug 01, 2026 |
| CVE-2026-16614 | MEDIUM | 4.9 | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all … | Aug 01, 2026 |
| CVE-2026-16144 | HIGH | 8.1 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … | Aug 01, 2026 |
| CVE-2026-16091 | MEDIUM | 6.4 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | Aug 01, 2026 |
| CVE-2026-16090 | MEDIUM | 6.4 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' … | Aug 01, 2026 |
| CVE-2026-16087 | MEDIUM | 6.5 | The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Parameter in all versions … | Aug 01, 2026 |
| CVE-2026-15964 | CRITICAL | 9.8 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, … | Aug 01, 2026 |
| CVE-2026-15951 | MEDIUM | 4.9 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due … | Aug 01, 2026 |