Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42183
Total
3433
Critical
12465
High
12416
Medium
CVE ID Severity Score Description Published
CVE-2026-81887 UNKNOWN Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the … Aug 31, 2026
CVE-2026-81780 CRITICAL 10.0 Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. Aug 31, 2026
CVE-2026-81779 CRITICAL 10.0 Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through … Aug 31, 2026
CVE-2026-81778 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions. Aug 31, 2026
CVE-2026-81768 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. Aug 31, 2026
CVE-2026-81765 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. Aug 31, 2026
CVE-2026-81764 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. Aug 31, 2026
CVE-2026-81763 CRITICAL 9.3 Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. Aug 31, 2026
CVE-2026-81762 MEDIUM 6.5 Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. Aug 31, 2026
CVE-2026-81758 MEDIUM 6.3 Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. Aug 31, 2026
CVE-2026-81756 CRITICAL 9.3 Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. Aug 31, 2026
CVE-2026-81298 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. Aug 31, 2026
CVE-2026-81297 HIGH 7.5 Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. Aug 31, 2026
CVE-2026-81296 HIGH 7.5 Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. Aug 31, 2026
CVE-2026-81293 CRITICAL 9.3 Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. Aug 31, 2026
CVE-2026-81291 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. Aug 31, 2026
CVE-2026-81290 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. Aug 31, 2026
CVE-2026-81287 HIGH 8.5 Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. Aug 31, 2026
CVE-2026-81280 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. Aug 31, 2026
CVE-2026-81278 MEDIUM 5.4 Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1. Aug 31, 2026
CVE-2026-79483 MEDIUM 5.3 FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators … Aug 31, 2026
CVE-2026-79408 CRITICAL 9.8 An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. Aug 31, 2026
CVE-2026-79407 HIGH 7.5 A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() … Aug 31, 2026
CVE-2026-75594 UNKNOWN Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to … Aug 31, 2026
CVE-2026-75592 UNKNOWN Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks … Aug 31, 2026