Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81887 | UNKNOWN | — | Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the … | Aug 31, 2026 |
| CVE-2026-81780 | CRITICAL | 10.0 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | Aug 31, 2026 |
| CVE-2026-81779 | CRITICAL | 10.0 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through … | Aug 31, 2026 |
| CVE-2026-81778 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions. | Aug 31, 2026 |
| CVE-2026-81768 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | Aug 31, 2026 |
| CVE-2026-81765 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | Aug 31, 2026 |
| CVE-2026-81764 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | Aug 31, 2026 |
| CVE-2026-81763 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | Aug 31, 2026 |
| CVE-2026-81762 | MEDIUM | 6.5 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | Aug 31, 2026 |
| CVE-2026-81758 | MEDIUM | 6.3 | Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | Aug 31, 2026 |
| CVE-2026-81756 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | Aug 31, 2026 |
| CVE-2026-81298 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | Aug 31, 2026 |
| CVE-2026-81297 | HIGH | 7.5 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | Aug 31, 2026 |
| CVE-2026-81296 | HIGH | 7.5 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | Aug 31, 2026 |
| CVE-2026-81293 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | Aug 31, 2026 |
| CVE-2026-81291 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | Aug 31, 2026 |
| CVE-2026-81290 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | Aug 31, 2026 |
| CVE-2026-81287 | HIGH | 8.5 | Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. | Aug 31, 2026 |
| CVE-2026-81280 | MEDIUM | 6.5 | Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | Aug 31, 2026 |
| CVE-2026-81278 | MEDIUM | 5.4 | Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1. | Aug 31, 2026 |
| CVE-2026-79483 | MEDIUM | 5.3 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators … | Aug 31, 2026 |
| CVE-2026-79408 | CRITICAL | 9.8 | An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. | Aug 31, 2026 |
| CVE-2026-79407 | HIGH | 7.5 | A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() … | Aug 31, 2026 |
| CVE-2026-75594 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to … | Aug 31, 2026 |
| CVE-2026-75592 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks … | Aug 31, 2026 |