Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51159
Total
4081
Critical
15166
High
14812
Medium
CVE ID Severity Score Description Published
CVE-2026-15444 MEDIUM 4.9 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions … Jul 28, 2026
CVE-2026-15411 MEDIUM 5.3 The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in … Jul 28, 2026
CVE-2026-15025 HIGH 7.5 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, … Jul 28, 2026
CVE-2026-13440 HIGH 7.2 The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting … Jul 28, 2026
CVE-2026-13110 MEDIUM 5.3 The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing … Jul 28, 2026
CVE-2026-65880 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms … Jul 28, 2026
CVE-2026-63303 UNKNOWN — A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before … Jul 28, 2026
CVE-2026-63302 UNKNOWN — Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary … Jul 28, 2026
CVE-2026-63301 UNKNOWN — In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API … Jul 28, 2026
CVE-2026-18029 UNKNOWN — Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and … Jul 28, 2026
CVE-2026-18028 UNKNOWN — The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in … Jul 28, 2026
CVE-2026-17072 LOW 3.3 A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a … Jul 28, 2026
CVE-2026-65624 UNKNOWN — Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 … Jul 28, 2026
CVE-2026-59248 UNKNOWN — Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or … Jul 28, 2026
CVE-2026-58246 MEDIUM 4.3 SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a … Jul 28, 2026
CVE-2026-16462 CRITICAL 9.8 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands. Jul 28, 2026
CVE-2026-14785 HIGH 7.5 The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 … Jul 28, 2026
CVE-2026-14328 HIGH 8.8 The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … Jul 28, 2026
CVE-2026-11841 CRITICAL 9.4 An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A … Jul 28, 2026
CVE-2026-11598 MEDIUM 5.0 The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to … Jul 28, 2026
CVE-2026-10207 HIGH 7.5 The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization … Jul 28, 2026
CVE-2026-9680 MEDIUM 5.8 Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on … Jul 28, 2026
CVE-2026-8167 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News … Jul 28, 2026
CVE-2026-61376 HIGH 7.2 ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS … Jul 28, 2026
CVE-2026-59764 HIGH 7.2 ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command … Jul 28, 2026